UNKNOWN npm
SQL Injection in sequelize
GHSA-x2jc-pwfj-h9p3 · CVE-2016-10554
Published · Modified
Description
Affected versions of sequelize use MySQL's backslash-based escape syntax when connecting to SQLite, despite the fact that SQLite uses PostgreSQL's escape syntax, which can result in a SQL Injection vulnerability.
Recommendation
Update to version 1.7.0-alpha3 or later.
Ready to move
Start Securing
Free, no credit card | First findings in minutes