Description
SQL injection vulnerability in the model.increment and model.decrement function in ThinkJS 3.2.10 allows remote attackers to execute arbitrary SQL commands via the step parameter.
Remediation
References
https://blog.jiguang.xyz/posts/thinkjs-sql-injection/
https://github.com/thinkjs/thinkjs
Related Vulnerabilities
CVE-2022-25885 Vulnerability in npm package hummus
CVE-2022-43429 Vulnerability in maven package com.compuware.jenkins:compuware-topaz-for-total-test
CVE-2022-30500 Vulnerability in maven package com.jflyfox:jflyfox_jfinal
CVE-2021-41862 Vulnerability in maven package com.googlecode.aviator:aviator
CVE-2022-36915 Vulnerability in maven package org.jenkins-ci.plugins:android-signing