Description
knex.js versions before 0.19.5 are vulnerable to SQL Injection attack. Identifiers are escaped incorrectly as part of the MSSQL dialect, allowing attackers to craft a malicious query to the host DB.
Remediation
References
https://snyk.io/vuln/SNYK-JS-KNEX-471962
Related Vulnerabilities
CVE-2023-47325 Vulnerability in maven package org.silverpeas.core:silverpeas-core-web
CVE-2023-36479 Vulnerability in maven package org.eclipse.jetty.ee9:jetty-ee9-servlets
CVE-2019-10759 Vulnerability in npm package safer-eval
CVE-2020-29455 Vulnerability in npm package liveaddress
CVE-2020-5259 Vulnerability in maven package org.webjars.npm:dojox