← Back to CVE List

CVE-2018-3754

Published: 2018-07-03T21:29Z
Last Modified: 2024-11-21T04:06Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Node.js third-party module query-mysql versions 0.0.0, 0.0.1, and 0.0.2 are vulnerable to an SQL injection vulnerability due to lack of user input sanitization. This may allow an attacker to run arbitrary SQL queries when fetching data from database. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt