Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9893-cg5g-qpvh

Опубликовано: 18 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

calculator-boilerplate v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the eval function at /routes/calculator.js. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the input field.

calculator-boilerplate v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the eval function at /routes/calculator.js. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the input field.

EPSS

Процентиль: 86%
0.02884
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-95

Связанные уязвимости

CVSS3: 9.8
nvd
больше 1 года назад

calculator-boilerplate v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the eval function at /routes/calculator.js. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the input field.

EPSS

Процентиль: 86%
0.02884
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-95