parse-server is a Parse Server for Node.js / Express. This vulnerability allows SQL injection when Parse Server is configured to use the PostgreSQL database. The vulnerability has been fixed in 6.5.0 and 7.0.0-alpha.20.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-03-01T17:48:52.919Z

Updated: 2024-08-22T18:28:04.258Z

Reserved: 2024-02-22T18:08:38.875Z

Link: CVE-2024-27298

cve-icon Vulnrichment

Updated: 2024-08-02T00:27:59.923Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-01T18:15:28.913

Modified: 2024-11-21T09:04:16.450

Link: CVE-2024-27298

cve-icon Redhat

No data.