QID 981151
QID 981151: Nodejs (npm) Security Update for query-mysql (GHSA-9mr8-6prp-gwjv)
All versions of `query-mysql` are vulnerable to SQL injection due to lack of user input sanitization allows to run arbitrary SQL queries when fetching data from database.
## Recommendation
No fix is currently available for this vulnerability. It is our recommendation to not install or use this module if user input is passed into this module.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-9mr8-6prp-gwjv for updates pertaining to this vulnerability.
Vendor References
- GHSA-9mr8-6prp-gwjv -
github.com/advisories/GHSA-9mr8-6prp-gwjv
CVEs related to QID 981151
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9mr8-6prp-gwjv | query-mysql |
|