CVEs affecting projects tracked on Release Alert, from NVD & OSV.
CVE-2015-1369 — HIGH severity vulnerability | Release Alert
CVE-2015-1369
7.5
HIGHCVSS v2
Published
January 27, 2015
Affected
2 projects
Assigned by
Red Hat
Severity scale
010
Description
SQL injection vulnerability in Sequelize before 2.0.0-rc7 for Node.js allows remote attackers to execute arbitrary SQL commands via the order parameter.
NPMSequelize is a promise-based Node.js ORM tool for Postgres, MySQL, MariaDB, SQLite, Microsoft SQL Server, Amazon Redshift and Snowflake’s Data Cloud. It features solid transaction support, relations, eager and lazy loading, read replication and more.
GitHubFeature-rich ORM for modern Node.js and TypeScript, it supports PostgreSQL (with JSON and JSONB support), MySQL, MariaDB, SQLite, MS SQL Server, Snowflake, Oracle DB, DB2 and DB2 for IBM i.