Description
Keys of objects in mysql node module v2.0.0-alpha7 and earlier are not escaped with `mysql.escape()` which could lead to SQL Injection.
Remediation
References
https://github.com/felixge/node-mysql/issues/342
https://nodesecurity.io/advisories/66
Related Vulnerabilities
CVE-2023-34612 Vulnerability in maven package com.helger.commons:ph-json
CVE-2018-14042 Vulnerability in maven package org.webjars.bowergithub.angular-ui:bootstrap
CVE-2020-7771 Vulnerability in npm package asciitable.js
CVE-2022-35980 Vulnerability in maven package org.opensearch.plugin:opensearch-security
CVE-2021-32850 Vulnerability in npm package @claviska/jquery-minicolors