GHSA-hx5x-49mm-vmhw

Suggest an improvement
Source
https://github.com/advisories/GHSA-hx5x-49mm-vmhw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-hx5x-49mm-vmhw/GHSA-hx5x-49mm-vmhw.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-hx5x-49mm-vmhw
Published
2020-09-03T02:36:43Z
Modified
2021-09-27T22:39:39Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
SQL Injection in sails-mysql
Details

Versions of sails-mysql prior to 0.10.8 are vulnerable to SQL Injection. The sort keyword is not properly sanitized and may allow attackers to inject SQL statements and execute arbitrary SQL queries

Recommendation

Upgrade to version 0.10.8 or later.

Database specific
{
    "cwe_ids": [
        "CWE-89"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2020-08-31T18:41:40Z",
    "nvd_published_at": null,
    "severity": "HIGH"
}
References

Affected packages

npm / sails-mysql

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.10.8

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-hx5x-49mm-vmhw/GHSA-hx5x-49mm-vmhw.json"