High severityNVD Advisory· Published Jan 27, 2015· Updated May 6, 2026
CVE-2015-1369
CVE-2015-1369
Description
SQL injection vulnerability in Sequelize before 2.0.0-rc7 for Node.js allows remote attackers to execute arbitrary SQL commands via the order parameter.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
sequelizenpm | < 2.0.0-rc8 | 2.0.0-rc8 |
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- github.com/sequelize/sequelize/pull/2919nvdExploitWEB
- nodesecurity.io/advisories/sequelize-sql-injection-ordernvdExploit
- github.com/advisories/GHSA-xqg8-cv3h-xppvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2015-1369ghsaADVISORY
- www.openwall.com/lists/oss-security/2015/01/23/2nvdWEB
- github.com/sequelize/sequelize/issues/2906ghsaWEB
- www.npmjs.com/advisories/33ghsaWEB
News mentions
0No linked articles in our index yet.