CVE Database
/

CVE-2019-10757

Back to search

CVE-2019-10757

Published: Oct 8, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

knex.js versions before 0.19.5 are vulnerable to SQL Injection attack. Identifiers are escaped incorrectly as part of the MSSQL dialect, allowing attackers to craft a malicious query to the host DB.

VendorProductVersions

n/a

knex.js

affected
All versions prior to version 0.19.5

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now