QID 980032
QID 980032: Nodejs (npm) Security Update for thinkjs (GHSA-q5mq-6fjg-4mw8)
SQL injection vulnerability in the model.increment and model.decrement function in ThinkJS 3.2.10 allows remote attackers to execute arbitrary SQL commands via the step parameter.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-q5mq-6fjg-4mw8 for updates pertaining to this vulnerability.
Vendor References
- GHSA-q5mq-6fjg-4mw8 -
github.com/advisories/GHSA-q5mq-6fjg-4mw8
CVEs related to QID 980032
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-q5mq-6fjg-4mw8 | thinkjs |
|