SQL Injection in mysql
Moderate severity
GitHub Reviewed
Published
Sep 1, 2020
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
May 29, 2018
Reviewed
Aug 31, 2020
Published to the GitHub Advisory Database
Sep 1, 2020
Last updated
Feb 1, 2023
Versions of
mysql
prior to 2.0.0-alpha8 are affected by a SQL Injection vulnerability in themysql.escape()
function, which does not properly escape object keys.Recommendation
Update to version 2.0.0-alpha8 or later.
References