Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20597
HistoryJun 24, 2019 - 7:18 a.m.

SQL Injection

2019-06-2407:18:07
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

EPSS

0.002

Percentile

57.0%

sequelize is vulnerable to sql injection attacks. The attacks are possible because the library does not escape the JSON path key provided by the user using postgres dialects in query-generator.js.

EPSS

0.002

Percentile

57.0%