Versions of sails-mysql prior to 0.10.8 are vulnerable to SQL Injection. The sort keyword is not properly sanitized and may allow attackers to inject SQL statements and execute arbitrary SQL queries
Upgrade to version 0.10.8 or later.
{
"cwe_ids": [
"CWE-89"
],
"github_reviewed": true,
"github_reviewed_at": "2020-08-31T18:41:40Z",
"nvd_published_at": null,
"severity": "HIGH"
}