Description
A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1. A specially-crafted Javascript file can lead to arbitrary code execution. An attacker can provide malicious input to trigger this vulnerability.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5373-1 | node-sqlite3 security update |
EUVD |
EUVD-2023-1051 | A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1. A specially-crafted Javascript file can lead to arbitrary code execution. An attacker can provide malicious input to trigger this vulnerability. |
Github GHSA |
GHSA-jqv5-7xpx-qj74 | sqlite vulnerable to code execution due to Object coercion |
References
History
No history.
Status: PUBLISHED
Assigner: talos
Published:
Updated: 2024-08-03T13:32:59.404Z
Reserved: 2022-10-20T15:24:15.340Z
Link: CVE-2022-43441
Updated: 2024-08-03T13:32:59.404Z
Status : Modified
Published: 2023-03-16T21:15:11.023
Modified: 2024-11-21T07:26:29.727
Link: CVE-2022-43441
No data.
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Github GHSA