UNKNOWN npm

SQL Injection in sequelize

GHSA-x2jc-pwfj-h9p3 · CVE-2016-10554

Published · Modified

Description

Affected versions of sequelize use MySQL's backslash-based escape syntax when connecting to SQLite, despite the fact that SQLite uses PostgreSQL's escape syntax, which can result in a SQL Injection vulnerability.

Recommendation

Update to version 1.7.0-alpha3 or later.

Ready to move

Start Securing

Free, no credit card | First findings in minutes