CVE-2016-10550: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
(updated )
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS If user input goes into the limit
or order
parameters, a malicious user can put in their own SQL statements. This affects sequelize 3.16.0 and earlier.
References
Detect and mitigate CVE-2016-10550 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →