Description
Keys of objects in mysql node module v2.0.0-alpha7 and earlier are not escaped with `mysql.escape()` which could lead to SQL Injection.
Remediation
References
https://github.com/felixge/node-mysql/issues/342
https://nodesecurity.io/advisories/66
Related Vulnerabilities
CVE-2022-23458 Vulnerability in npm package tui-grid
CVE-2022-37724 Vulnerability in maven package wonder.utilities:utilities
CVE-2022-0722 Vulnerability in maven package org.webjars.npm:parse-url
CVE-2020-28498 Vulnerability in maven package org.webjars.npm:elliptic
CVE-2020-15252 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore