Description
An SQL injection vulnerability exists in the @veramo/data-store package that allows any authenticated user to execute arbitrary SQL queries against the database. The vulnerability is caused by insufficient validation of the column parameter in the order array of query requests.
Recommendation
Update the @veramo/data-store package to the latest compatible version. Followings are version details:
- Affected version(s): < 6.0.2
- Patched version(s): 6.0.2
References
Could your website be exposed too?
SmartScanner can check your website for Veramo is Vulnerable to SQL Injection in Veramo Data Store ORM and gives you actionable findings to investigate.
Start a free scanRelated Issues
- @saltcorn/data vulnerable to SQL Injection via jsexprToSQL Literal Handler - Vulnerability
- TypeORM: SQL Injection in UpdateQueryBuilder/SoftDeleteQueryBuilder orderBy (MySQL/MariaDB) - Vulnerability
- @saltcorn/server Remote Code Execution (RCE) / SQL injection via prototype pollution by manipulating `lang` and `defst - Vulnerability
- Failure to sanitize quotes which can lead to sql injection in squel - Vulnerability


