SQL injection In sequelize
Description
SQL Injection in sequelize
Versions 2.0.0-rc-7 and earlier of sequelize are affected by a SQL injection vulnerability when user input is passed into the order parameter.
Proof of Concept
Test.findAndCountAll({ where: { id :1 }, order : [['id', 'UNTRUSTED USER INPUT']] })
Recommendation
Update to version 2.0.0-rc8 or later
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 2.0.0-rc8 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3. 4.