Description
Keys of objects in mysql node module v2.0.0-alpha7 and earlier are not escaped with `mysql.escape()` which could lead to SQL Injection.
Remediation
References
https://github.com/felixge/node-mysql/issues/342
https://nodesecurity.io/advisories/66
Related Vulnerabilities
CVE-2019-10062 Vulnerability in npm package aurelia-framework
CVE-2017-16212 Vulnerability in npm package ltt
CVE-2019-5786 Vulnerability in maven package org.webjars.npm:electron
CVE-2022-48285 Vulnerability in maven package org.webjars:jszip
CVE-2021-27582 Vulnerability in maven package org.mitre:openid-connect-server