Description
Due to improper input validation in the Feathers js library, it is possible to perform a SQL injection attack on the back-end database, in case the feathers-sequelize package is used.
Remediation
References
https://csirt.divd.nl/CVE-2022-2422
https://csirt.divd.nl/DIVD-2022-00020
Related Vulnerabilities
CVE-2022-21129 Vulnerability in npm package nemo-appium
CVE-2021-30074 Vulnerability in npm package docsify
CVE-2018-1000844 Vulnerability in maven package com.squareup.retrofit2:converter-jaxb
CVE-2022-37616 Vulnerability in npm package xmldom
CVE-2020-25649 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind