Description
Due to improper input validation in the Feathers js library, it is possible to perform a SQL injection attack on the back-end database, in case the feathers-sequelize package is used.
Remediation
References
https://csirt.divd.nl/DIVD-2022-00020
https://csirt.divd.nl/CVE-2022-2422
Related Vulnerabilities
CVE-2023-33202 Vulnerability in maven package org.bouncycastle:bc-fips
CVE-2018-5158 Vulnerability in npm package pdfjs-dist
CVE-2020-7743 Vulnerability in maven package org.webjars.npm:mathjs
CVE-2022-25167 Vulnerability in maven package org.apache.flume.flume-ng-sources:flume-jms-source
CVE-2021-21162 Vulnerability in maven package org.webjars.npm:electron