This advisory has been withdrawn because it is a duplicate of GHSA-f598-mfpv-gmfx. This link is maintained to preserve external references.
Due to improper attribute filtering in the sequelize js library, an attacker can peform SQL injections. This issue can be mitigated by not accepting untrusted input.
{
"cwe_ids": [
"CWE-790"
],
"github_reviewed": true,
"github_reviewed_at": "2023-02-22T23:16:24Z",
"nvd_published_at": "2023-02-16T15:15:00Z",
"severity": "CRITICAL"
}