CVE-2016-10551
Summary
| CVE | CVE-2016-10551 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-05-29 20:29:00 UTC |
| Updated | 2019-10-09 23:16:00 UTC |
| Description | waterline-sequel is a module that helps generate SQL statements for Waterline apps Any user input that goes into Waterline's `like`, `contains`, `startsWith`, or `endsWith` will end up in waterline-sequel with the potential for malicious code. A malicious user can input their own SQL statements in waterline-sequel 0.50 that will get executed and have full access to the database. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| SQL Injection with default blueprints in Waterline · Issue #5347 · balderdashy/sails · GitHub |
MISC |
github.com |
Exploit, Issue Tracking, Third Party Advisory |
| Overview |
MISC |
nodesecurity.io |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 983933 Nodejs (npm) Security Update for waterline-sequel (GHSA-cgpp-wm2h-6hqx)