CVE-2016-20018

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
19/12/2022
Last modified:
23/11/2023

Description

Knex Knex.js through 2.3.0 has a limited SQL injection vulnerability that can be exploited to ignore the WHERE clause of a SQL query.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:knexjs:knex:*:*:*:*:*:node.js:*:* 2.3.0 (including)