Description


The crud-query-parser library parses query parameters from HTTP requests and converts them to database queries. Improper neutralization of the order/sort parameter in the TypeORM adapter, which allows SQL injection. You are impacted by this vulnerability if you are using the TypeORM adapter, ordering is enabled and you have not set-up a property filter. This vulnerability is fixed in 0.1.0.

Related CPE's


Could not find any relations

Weaknesses



CWE-89

CVSS impact metrics


CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

9.3 · Critical

Information


Source identifier

[email protected]

Vulnerability status

Awaiting analysis

Published

2025-04-08T13:15:50.430Z

11 months ago

Last modified

2025-04-08T16:13:53.347Z

11 months ago