parse-server is vulnerable to SQL Injection
99
Critical Risk
Versions of this package impacted by this issue are vulnerable to SQL Injection through a malicious PostgreSQL statement containing multiple quoted strings. This vulnerability occurs only when using the PostgreSQL engine.
You are affected if you are using a version which is within vulnerability ranges and if you are using the PostgreSQL engine.
parse-server is vulnerable to SQL Injection in versions 2.2.14 - 6.4.0.
Upgrade the parse-server library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant