CVE-2023-22578

Due to improper artibute filtering in the sequalize js library, can a attacker peform SQL injections.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
DIVDCNA
10 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 28%
VendorProductVersion
sequelizejssequelize
𝑥
< 6.29.0
sequelizejssequelize
7.0.0:alpha1
sequelizejssequelize
7.0.0:alpha10
sequelizejssequelize
7.0.0:alpha11
sequelizejssequelize
7.0.0:alpha12
sequelizejssequelize
7.0.0:alpha13
sequelizejssequelize
7.0.0:alpha14
sequelizejssequelize
7.0.0:alpha15
sequelizejssequelize
7.0.0:alpha16
sequelizejssequelize
7.0.0:alpha17
sequelizejssequelize
7.0.0:alpha18
sequelizejssequelize
7.0.0:alpha19
sequelizejssequelize
7.0.0:alpha2
sequelizejssequelize
7.0.0:alpha2.1
sequelizejssequelize
7.0.0:alpha2.2
sequelizejssequelize
7.0.0:alpha3
sequelizejssequelize
7.0.0:alpha4
sequelizejssequelize
7.0.0:alpha5
sequelizejssequelize
7.0.0:alpha6
sequelizejssequelize
7.0.0:alpha7
sequelizejssequelize
7.0.0:alpha8
sequelizejssequelize
7.0.0:alpha9
sequelizejssequelize
7.0.0:oc_test_1
sequelizejssequelize
7.0.0:oc_test_2
sequelizejssequelize
7.0.0:oc_test_3
sequelizejssequelize
7.0.0:oc_test_4
𝑥
= Vulnerable software versions