Vulnerabilities/

Failure to sanitize quotes which can lead to sql injection in squel

Severity:
High

Description

All versions of squel are vulnerable to sql injection.

The squel package does not properly escape user provided input when provided using the setFields method. This could lead to sql injection if the query was then executed.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
squel
Anything's wrong? Let us know Last updated on January 09, 2023