CVE-2015-1369: SQL Injection
Published Jan 27, 2015
·Updated
SQL injection vulnerability in Sequelize before 2.0.0-rc7 for Node.js allows remote attackers to execute arbitrary SQL commands via the order parameter.
Affected Software
1 affected component
Sequelize Project Sequelize<=2.0.0
Event History
Jan 27, 2015
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1369?
CVE-2015-1369 has been classified as a critical vulnerability due to its potential to allow remote code execution via SQL injection.
2
How do I fix CVE-2015-1369?
To mitigate CVE-2015-1369, upgrade Sequelize to version 2.0.0-rc7 or later.
3
What type of attack does CVE-2015-1369 allow?
CVE-2015-1369 allows an attacker to execute arbitrary SQL commands by exploiting the order parameter.
4
Which versions of Sequelize are affected by CVE-2015-1369?
CVE-2015-1369 affects all versions of Sequelize prior to 2.0.0-rc7.
5
Can CVE-2015-1369 be exploited remotely?
Yes, CVE-2015-1369 can be exploited by remote attackers.