SQL Injection in query-mysql
High severity
GitHub Reviewed
Published
Sep 10, 2018
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Published to the GitHub Advisory Database
Sep 10, 2018
Reviewed
Jun 16, 2020
Last updated
Jan 9, 2023
All versions of
query-mysql
are vulnerable to SQL injection due to lack of user input sanitization allows to run arbitrary SQL queries when fetching data from database.Recommendation
No fix is currently available for this vulnerability. It is our recommendation to not install or use this module if user input is passed into this module.
References