Описание
pg-promise SQL Injection vulnerability
pg-promise before 11.5.5 is vulnerable to SQL Injection due to improper handling of negative numbers.
Пакеты
Наименование
pg-promise
npm
Затронутые версииВерсия исправления
< 11.5.5
11.5.5
Связанные уязвимости
CVSS3: 5.4
nvd
8 месяцев назад
pg-promise before 11.5.5 is vulnerable to SQL Injection due to improper handling of negative numbers.