GHSA-9mr8-6prp-gwjv

Suggest an improvement
Source
https://github.com/advisories/GHSA-9mr8-6prp-gwjv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/09/GHSA-9mr8-6prp-gwjv/GHSA-9mr8-6prp-gwjv.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-9mr8-6prp-gwjv
Aliases
  • CVE-2018-3754
Published
2018-09-10T15:20:30Z
Modified
2023-11-08T04:00:19.085815Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
SQL Injection in query-mysql
Details

All versions of query-mysql are vulnerable to SQL injection due to lack of user input sanitization allows to run arbitrary SQL queries when fetching data from database.

Recommendation

No fix is currently available for this vulnerability. It is our recommendation to not install or use this module if user input is passed into this module.

Database specific
{
    "cwe_ids": [
        "CWE-89"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2020-06-16T21:28:59Z",
    "nvd_published_at": null,
    "severity": "HIGH"
}
References

Affected packages

npm / query-mysql

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
0.0.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/09/GHSA-9mr8-6prp-gwjv/GHSA-9mr8-6prp-gwjv.json"