Lucene search

K
cvelistHackeroneCVELIST:CVE-2018-3754
HistoryMay 24, 2018 - 12:00 a.m.

CVE-2018-3754

2018-05-2400:00:00
hackerone
www.cve.org

8.9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.3%

Node.js third-party module query-mysql versions 0.0.0, 0.0.1, and 0.0.2 are vulnerable to an SQL injection vulnerability due to lack of user input sanitization. This may allow an attacker to run arbitrary SQL queries when fetching data from database.

8.9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.3%