Vendor
A SQL injection vulnerability in the SelectQuery component of the node-sql-query library allows remote attackers to execute arbitrary SQL commands via manipulated request parameters.