Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS04cGg4LTlxMmotYzNycc4AAwx-
nodebatis SQL Injection vulnerability
A vulnerability was found in PeterMu nodebatis up to 2.1.x. It has been classified as critical. Affected is an unknown function. The manipulation leads to sql injection. Upgrading to version 2.2.0 can address this issue. The name of the patch is 6629ff5b7e3d62ad8319007a54589ec1f62c7c35. It is recommended to upgrade the affected component. VDB-217554 is the identifier assigned to this vulnerability.
Permalink: https://github.com/advisories/GHSA-8ph8-9q2j-c3rqJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04cGg4LTlxMmotYzNycc4AAwx-
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Critical
Classification: General
Published: 5 months ago
Updated: 4 months ago
CVSS Score: 9.8
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Identifiers: GHSA-8ph8-9q2j-c3rq, CVE-2018-25066
References:
- https://nvd.nist.gov/vuln/detail/CVE-2018-25066
- https://github.com/PeterMu/nodebatis/commit/6629ff5b7e3d62ad8319007a54589ec1f62c7c35
- https://github.com/PeterMu/nodebatis/releases/tag/v2.2.0
- https://vuldb.com/?ctiid.217554
- https://vuldb.com/?id.217554
- https://github.com/advisories/GHSA-8ph8-9q2j-c3rq
Affected Packages
npm:nodebatis
Versions: < 2.2.0Fixed in: 2.2.0