PT-2018-4729 · Sailjs · Waterline-Sequel

Jamsea

·

Published

2018-05-29

·

Updated

2019-10-09

·

CVE-2016-10551

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions waterline-sequel versions 0.50
Description The issue allows malicious users to input their own SQL statements, which can be executed and provide full access to the database. This occurs when user input is passed into the like, contains, startsWith, or endsWith methods in waterline-sequel.
Recommendations Upgrade to at least version 0.5.1

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-10551
GHSA-CGPP-WM2H-6HQX

Affected Products

Waterline-Sequel