Security Advisory

CVE-2024-27298

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-03-01 17:48:52
Last updated 2024-08-22 18:28:04
Assigner GitHub_M
CVSS score 10.0
State PUBLISHED

Description

parse-server is a Parse Server for Node.js / Express. This vulnerability allows SQL injection when Parse Server is configured to use the PostgreSQL database. The vulnerability has been fixed in 6.5.0 and 7.0.0-alpha.20.