CVE-2024-27298 | parse-server up to 6.4.x/7.0.0-alpha.19 on Node.js PostgreSQL sql injection (GHSA-6927-3vr9-fxf2)
A vulnerability categorized as critical has been discovered in parse-server up to 6.4.x/7.0.0-alpha.19 on Node.js. The impacted element is an unknown function of the component PostgreSQL Handler. The manipulation results in sql injection.
This vulnerability was named CVE-2024-27298. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.