Description
Due to improper input validation in the Feathers js library, it is possible to perform a SQL injection attack on the back-end database, in case the feathers-sequelize package is used.
Remediation
References
https://csirt.divd.nl/CVE-2022-2422
https://csirt.divd.nl/DIVD-2022-00020
Related Vulnerabilities
CVE-2021-25864 Vulnerability in npm package node-red-contrib-huemagic
CVE-2019-10422 Vulnerability in maven package org.ukiuni.callotherjenkins:call-remote-job-plugin
CVE-2019-15609 Vulnerability in npm package kill-port-process
CVE-2017-16138 Vulnerability in maven package org.webjars.npm:mime
CVE-2022-24278 Vulnerability in npm package convert-svg-core