Vulnerabilities/

SQL Injection and Cross-site Scripting in class-validator

Severity:
High

Description

In TypeStack class-validator, validate() input validation can be bypassed because certain internal attributes can be overwritten via a conflicting name.

Recommendation

Update the class-validator package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
class-validator
Anything's wrong? Let us know Last updated on January 27, 2023

This issue is available in SmartScanner Professional

See Pricing