Collected research
Prepared Statements? Prepared to Be Vulnerable.
The Node.js mysql and mysql2 drivers convert JavaScript objects and arrays into SQL fragments by default, so submitting a JSON object where a string is expected turns a correctly parameterised prepared statement into attacker-controlled SQL. It enables mass reads, updates and deletes, and in the reported case a password-reset bypass and account takeover.
Record
- Researcher
- Balazs Bucsay
- Published by
- blog.mantrainfosec.com
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Balazs Bucsay, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .