« Volver al listado

CVE-2015-9244

Estado: ModificadaCrítica (9.8)—

Keys of objects in mysql node module v2.0.0-alpha7 and earlier are not escaped with `mysql.escape()` which could lead to SQL Injection.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2015-9244",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": true,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "support@hackerone.com",
      "affectedData": [
        {
          "vendor": "HackerOne",
          "product": "mysql node module",
          "versions": [
            {
              "status": "affected",
              "version": "<=v2.0.0-alpha7"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-05-29T20:29:00.597",
  "references": [
    {
      "url": "https://github.com/felixge/node-mysql/issues/342",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "support@hackerone.com"
    },
    {
      "url": "https://nodesecurity.io/advisories/66",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "support@hackerone.com"
    },
    {
      "url": "https://github.com/felixge/node-mysql/issues/342",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://nodesecurity.io/advisories/66",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "support@hackerone.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Keys of objects in mysql node module v2.0.0-alpha7 and earlier are not escaped with `mysql.escape()` which could lead to SQL Injection."
    },
    {
      "lang": "es",
      "value": "Las claves de objetos en el módulo mysql node en versiones v2.0.0-alpha7 y anteriores no se escapan con \"mysql.escape()\", lo que podría conducir a una inyección SQL."
    }
  ],
  "lastModified": "2026-06-17T00:36:07.507",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mysqljs:mysql:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "57E168F5-0917-4659-8A22-5B6C8C87C1A0",
              "versionEndIncluding": "0.9.6"
            },
            {
              "criteria": "cpe:2.3:a:mysqljs:mysql:2.0.0:alpha:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "604E8416-EB30-40D2-8239-63CB1EC08292"
            },
            {
              "criteria": "cpe:2.3:a:mysqljs:mysql:2.0.0:alpha2:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "295CD5DB-8252-4CDC-B6D6-F41DBB7F8C0E"
            },
            {
              "criteria": "cpe:2.3:a:mysqljs:mysql:2.0.0:alpha3:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6AB6AA92-476E-4C8E-B000-33D2DED72F07"
            },
            {
              "criteria": "cpe:2.3:a:mysqljs:mysql:2.0.0:alpha4:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E3A25E77-93C4-4852-8289-D09528EDE310"
            },
            {
              "criteria": "cpe:2.3:a:mysqljs:mysql:2.0.0:alpha7:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "295749A1-E344-419C-81C3-FA170D4E85DA"
            },
            {
              "criteria": "cpe:2.3:a:mysqljs:mysql:2.0.0:preview:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D432B4B8-B20D-4FA5-9E7F-404C7DA4031C"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "support@hackerone.com"
}