10

CVE-2023-22578

Due to improper artibute filtering in the sequalize js library, can a attacker peform SQL injections.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SequelizejsSequelize SwPlatformnode.js Version < 6.29.0
SequelizejsSequelize Version7.0.0 Updatealpha1 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha10 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha11 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha12 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha13 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha14 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha15 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha16 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha17 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha18 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha19 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha2 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha2.1 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha2.2 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha3 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha4 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha5 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha6 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha7 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha8 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha9 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updateoc_test_1 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updateoc_test_2 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updateoc_test_3 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updateoc_test_4 SwPlatformnode.js
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.394
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
csirt@divd.nl 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-790 Improper Filtering of Special Elements

The product receives data from an upstream component, but does not filter or incorrectly filters special elements before sending it to a downstream component.