Описание
OS Command Injection in node-key-sender
node-key-sender through 1.0.11 is vulnerable to Command Injection. It allows execution of arbitrary commands via the 'arrParams' argument in the 'execute()' function.
Пакеты
Наименование
node-key-sender
npm
Затронутые версииВерсия исправления
<= 1.0.11
Отсутствует
Связанные уязвимости
CVSS3: 9.8
nvd
почти 6 лет назад
node-key-sender through 1.0.11 is vulnerable to Command Injection. It allows execution of arbitrary commands via the 'arrParams' argument in the 'execute()' function.