Security Advisory

CVE-2019-10752

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-10-17 18:12:43
Last updated 2024-08-04 22:32:01
Assigner snyk
CVSS score not scored
State PUBLISHED

Description

Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escaping values properly when formatting sub paths for JSON queries for MySQL, MariaDB and SQLite.