CVE Database
/

CVE-2016-10551

Back to search

CVE-2016-10551

Published: May 29, 2018

Modified: Sep 16, 2024

PUBLISHED

Description

waterline-sequel is a module that helps generate SQL statements for Waterline apps Any user input that goes into Waterline's `like`, `contains`, `startsWith`, or `endsWith` will end up in waterline-sequel with the potential for malicious code. A malicious user can input their own SQL statements in waterline-sequel 0.50 that will get executed and have full access to the database.

VendorProductVersions

HackerOne

waterline-sequel node module

affected
0.5.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now