CPE
The MariaDB Connector/Node.js fails to properly escape input parameters for the text protocol when NO_BACKSLASH_ESCAPES mode is enabled, allowing attackers to perform SQL injection via standard placeholder APIs.