Description
Due to improper input validation in the Feathers js library, it is possible to perform a SQL injection attack on the back-end database, in case the feathers-sequelize package is used.
Remediation
References
https://csirt.divd.nl/CVE-2022-2422
https://csirt.divd.nl/DIVD-2022-00020
Related Vulnerabilities
CVE-2018-3732 Vulnerability in npm package resolve-path
CVE-2020-7720 Vulnerability in maven package org.webjars.npm:node-forge
CVE-2018-19057 Vulnerability in maven package org.webjars.npm:simplemde
CVE-2020-8237 Vulnerability in maven package org.webjars.bower:json-bigint
CVE-2020-15092 Vulnerability in npm package @knight-lab/timelinejs