CRITICAL 9.8 npm

SQL Injection in typeorm

GHSA-w7q7-vjp8-7jv4

Published · Modified

Description

Versions of typeorm before 0.1.15 are vulnerable to SQL Injection. Field names are not properly validated allowing attackers to inject SQL statements and execute arbitrary SQL queries.

Recommendation

Upgrade to version 0.1.15

Ready to move

Start Securing

Free, no credit card | First findings in minutes