Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2023-25813

Sequelize is a Node.js ORM tool. In versions prior to 6.19.1 a SQL injection exploit exists related to replacements. Parameters which are passed through replacements are not properly escaped which can lead to arbitrary SQL injection depending on the specific queries in use. The issue has been fixed in Sequelize 6.19.1. Users are advised to upgrade. Users unable to upgrade should not use the `replacements` and the `where` option in the same query.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.047
EPSS Ranking 88.7%
CVSS Severity
CVSS v3 Score 10.0
Products affected by CVE-2023-25813


Contact Us

Shodan ® - All rights reserved