← back
CVE-2016-10554

CVE-2016-10554

EPSS 1.9%CWE-89
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS. Before version 1.7.0-alpha3, sequelize defaulted SQLite to use MySQL backslash escaping, even though SQLite uses Postgres escaping.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →