Description
Due to improper input validation in the Feathers js library, it is possible to perform a SQL injection attack on the back-end database, in case the feathers-sequelize package is used.
Remediation
References
https://csirt.divd.nl/CVE-2022-2422
https://csirt.divd.nl/DIVD-2022-00020
Related Vulnerabilities
CVE-2019-1003031 Vulnerability in maven package org.jenkins-ci.plugins:matrix-project
CVE-2020-36321 Vulnerability in maven package com.vaadin:flow-server
CVE-2020-15779 Vulnerability in npm package socket.io-file
CVE-2015-8851 Vulnerability in maven package org.webjars.bower:node-uuid
CVE-2023-26486 Vulnerability in maven package org.webjars.bowergithub.vega:vega