Логотип exploitDog
bind:CVE-2022-33171
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-33171

Количество 2

Количество 2

nvd логотип

CVE-2022-33171

больше 3 лет назад

The findOne function in TypeORM before 0.3.0 can either be supplied with a string or a FindOneOptions object. When input to the function is a user-controlled parsed JSON object, supplying a crafted FindOneOptions instead of an id string leads to SQL injection. NOTE: the vendor's position is that the user's application is responsible for input validation

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-fx4w-v43j-vc45

больше 3 лет назад

SQL injection in typeORM

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-33171

The findOne function in TypeORM before 0.3.0 can either be supplied with a string or a FindOneOptions object. When input to the function is a user-controlled parsed JSON object, supplying a crafted FindOneOptions instead of an id string leads to SQL injection. NOTE: the vendor's position is that the user's application is responsible for input validation

CVSS3: 9.8
6%
Низкий
больше 3 лет назад
github логотип
GHSA-fx4w-v43j-vc45

SQL injection in typeORM

CVSS3: 9.8
6%
Низкий
больше 3 лет назад

Уязвимостей на страницу