Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20598
HistoryJun 24, 2019 - 8:24 a.m.

SQL Injection

2019-06-2408:24:13
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

EPSS

0.002

Percentile

56.0%

sequelize is vulnerable to sql injection attacks. The attacks are possible because the library does not properly escape the JSON path key provided by user using mariadb dialects in query-generator.js.

EPSS

0.002

Percentile

56.0%