Description
SQL injection vulnerability in the model.increment and model.decrement function in ThinkJS 3.2.10 allows remote attackers to execute arbitrary SQL commands via the step parameter.
Remediation
References
https://blog.jiguang.xyz/posts/thinkjs-sql-injection/
https://github.com/thinkjs/thinkjs
Related Vulnerabilities
CVE-2020-11079 Vulnerability in npm package dns-sync
CVE-2022-25644 Vulnerability in npm package @pendo324/get-process-by-name
CVE-2023-46494 Vulnerability in npm package @evershop/evershop
CVE-2020-24025 Vulnerability in maven package org.webjars.npm:node-sass
CVE-2022-23913 Vulnerability in maven package org.apache.activemq:artemis-core-client