Due to improper parameter filtering in the sequalize js library, can a attacker peform injection.
The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.
Link | Tags |
---|---|
https://csirt.divd.nl/CVE-2023-22579 | third party advisory |
https://csirt.divd.nl/DIVD-2022-00020/ | related third party advisory |