Description
SQL injection vulnerability in the model.increment and model.decrement function in ThinkJS 3.2.10 allows remote attackers to execute arbitrary SQL commands via the step parameter.
Remediation
References
https://blog.jiguang.xyz/posts/thinkjs-sql-injection/
https://github.com/thinkjs/thinkjs
Related Vulnerabilities
CVE-2022-35915 Vulnerability in maven package org.webjars.npm:openzeppelin__contracts
CVE-2023-26156 Vulnerability in maven package org.webjars.npm:chromedriver
CVE-2023-26486 Vulnerability in maven package org.webjars.npm:vega-functions
CVE-2015-0250 Vulnerability in maven package org.eclipse.birt.runtime:org.apache.batik.dom
CVE-2023-33695 Vulnerability in maven package cn.hutool:hutool-core