Nostalgic Primordial Monster
query-mysql

SQL Injection

Severity: high

Overview

All versions of query-mysql are vulnerable to SQL injection due to lack of user input sanitization allows to run arbitrary SQL queries when fetching data from database.

Remediation

No fix is currently available for this vulnerability. It is our recommendation to not install or use this module if user input is passed into this module.

Vulnerable versions

0.0.0
7 months ago
0.0.1
7 months ago
0.0.2
7 months ago

Unaffected versions

Resources

Advisory timeline

  1. published

    Advisory published
    May 16th, 2018
  2. reported

    May 16th, 2018