在 dresende/node-sql-query 0.1.25、0.1.26、0.1.27 和 0.1.28 版本中发现了一个漏洞。该漏洞影响组件“请求参数处理器”(Request Parameter Handler)中 lib/Select.js 文件下的 SelectQuery.from/SelectQuery.build 函数。利用该漏洞可导致 SQL 注入攻击,且攻击者能够远程发起攻击。目前相关利用代码已公开,可被直接使用。升级到 0.1.29 版本可修复此问题,修复补丁为 commit 3414c42f
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| dresende | node-sql-query | 0.1.25 |
affected |
0.1.26 |
affected | ||
0.1.27 |
affected | ||
0.1.28 |
affected | ||
0.1.29 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| dresende | node-sql-query | 0.1.25 |
cpe:2.3:a:dresende:node-sql-query:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
VULNERABLE: SQL injection via SelectQuery.build limit() leaked secret "PROOF_d039a98dc5ac5ea3" from secrets table through stacked-query injection
No comments yet