← Back to browse · API

CVE-2024-27298

Severity
CRITICAL
CVSS
10.0
EPSS
0.0103
Risk score
40.36
CISA KEV
No
PoC
No
Published
2024-03-01
Modified
2024-08-22
First seen
2026-08-07
Aliases
EUVD-2024-0843, GHSA-6927-3VR9-FXF2
Products
parse-community:parse-server, parse-community:parse-server 7.0.0-alpha.1, < 7.0.0-alpha.20, parse-community:parse-server < 6.5.0
Sources
euvd EUVD-2024-0843

Description

parse-server is a Parse Server for Node.js / Express. This vulnerability allows SQL injection when Parse Server is configured to use the PostgreSQL database. The vulnerability has been fixed in 6.5.0 and 7.0.0-alpha.20.

References