CVSS v3
9.8
CRITICAL
EPSS Score
3.9 %
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
Sequelize is a Node.js ORM tool. In versions prior to 6.19.1 a SQL injection exploit exists related to replacements. Parameters which are passed through replacements are not properly escaped which can lead to arbitrary SQL injection depending on the specific queries in use. The issue has been fixed in Sequelize 6.19.1. Users are advised to upgrade. Users unable to upgrade should not use the `replacements` and the `where` option in the same query.
Technical details
- Published
- 2023-02-22
Frequently asked questions
What is CVE-2023-25813?
Sequelize is a Node.js ORM tool. In versions prior to 6.19.1 a SQL injection exploit exists related to replacements. Parameters which are passed through replacements are not properly escaped which can lead to arbitrary SQL injection depending on the specific queries in use. The issue has been fixed in Sequelize 6.19.1. Users are advised to upgrade. Users unable to upgrade should not use the `replacements` and the `where` option in the same query.
Is CVE-2023-25813 actively exploited?
Active exploitation of CVE-2023-25813 has not been confirmed. The EPSS score is 3.9%, indicating the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2023-25813?
CVE-2023-25813 has a CVSS v3 base score of 9.8 (CRITICAL severity).
Is CVE-2023-25813 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 500 free checks/month · Free API key
Other 2023 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).