SQL Injection

Affecting loopback-connector-oracle package, versions <1.5.0

Do your applications use this vulnerable package? Test your applications

Overview

loopback-connector-oracle is Loopback Oracle Connector. Affected versions of the package are vulnerable to SQL injection attacks. User-supplied inputs are not properly sanitized before using it in SQL queries. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.

Remediation

Upgrade loopback-connector-oracle to version 1.5.0 or higher.

References

CVSS Score

6.5
medium severity
  • Attack Vector
    Network
  • Attack Complexity
    High
  • Privileges Required
    None
  • User Interaction
    None
  • Scope
    Unchanged
  • Confidentiality
    High
  • Integrity
    Low
  • Availability
    None
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Credit
Raymond Feng
CWE
CWE-89
Snyk ID
npm:loopback-connector-oracle:20150108
Disclosed
07 Jan, 2015
Published
04 Jan, 2017