CVE-2023-22578
Due to improper artibute filtering in the sequalize js library, can a attacker peform SQL injections.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.17%
- CWE
- CWE-790
- Published
- 2023-02-16
- Last modified
- 2026-03-13
Affected products
- Feathers-Sequalize Sequelize.js
Weakness type
Related vulnerabilities
- CVE-2021-43802 — Admin privilege escalation and arbitrary code execution via malicious *.etherpad imports
- CVE-2026-2328 — Backend Access Due to Insufficient Input Validation
- CVE-2025-27260 — Ericsson Indoor Connect 8855 - Improper Filtering of Special Elements Vulnerability
- CVE-2024-42416 — Multiple issues in ctl(4) CAM Target Layer
- CVE-2026-11331 — Potential wildcard CNAME RPZ policy bypass
- CVE-2025-15576 — Jail chroot escape via fd exchange with a different jail
- CVE-2026-9658 — Plack::Middleware::Security::Common versions before 0.13.1 for Perl did not block header injections in request paths
- CVE-2025-0431 — Enterprise Protection Backslash URL Rewrite Bypass