Junglewise Threat Intelligence

CVE-2020-21176: ThinkJS SQL injection in model.increment and model.decrement

CVE-2020-21176 · Severity: low · CVSS 3.1 · Published 2021-11-19

Vendors: npm.

Executive brief

ThinkJS is a popular Node.js web framework used to build web applications and APIs. A SQL injection vulnerability in its database model functions allows remote attackers to execute arbitrary SQL commands without authentication, potentially leading to unauthorized data access, modification, or deletion of database records.

Technical details

SQL injection vulnerability exists in the model.increment and model.decrement functions in ThinkJS 3.2.10 and earlier versions. The vulnerability is rooted in improper sanitization of the step parameter, which is passed unsanitized into SQL queries. An attacker can craft malicious input via the step parameter to execute arbitrary SQL commands remotely without authentication. The vulnerability affects all versions up to and including 3.2.14. Patches are available in later versions.

Affected products

  • ThinkJS ThinkJS 0-3.2.14

Timeline

  • 2021-02-01: disclosed: NVD published CVE-2020-21176
  • 2021-11-19: advisory: GHSA-q5mq-6fjg-4mw8 published

References