CVE-2019-10748

Publication date

2019-10-28 21:42:45

Family

snyk

State

PUBLISHED

Description

Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not being properly escaped for the MySQL/MariaDB dialects.