GHSA-8f93-rv4p-x4jw

Suggest an improvement
Source
https://github.com/advisories/GHSA-8f93-rv4p-x4jw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/06/GHSA-8f93-rv4p-x4jw/GHSA-8f93-rv4p-x4jw.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-8f93-rv4p-x4jw
Published
2019-06-12T16:36:52Z
Modified
2020-08-31T18:31:48Z
Summary
SQL Injection in sql
Details

All versions of sql are vulnerable to sql injection as it does not properly escape parameters when building SQL queries.

Recommendation

No fix is currently available for this vulnerability. It is our recommendation to not install or use this module until a fix is available.

Database specific
{
    "cwe_ids":  [
        "CWE-89"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2019-06-12T16:36:34Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / sql

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
0.78.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/06/GHSA-8f93-rv4p-x4jw/GHSA-8f93-rv4p-x4jw.json"