CVE-2023-22578: Sequelize - Default support for “raw attributes” when using parentheses

Severity: Critical

CVSS Score: 10

Due to improper artibute filtering in the sequalize js library, can a attacker peform SQL injections.