Описание
Improper Input Validation and Code Injection in pdf-image
Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based on untrusted user input.
Пакеты
Наименование
pdf-image
npm
Затронутые версииВерсия исправления
<= 2.0.0
Отсутствует
Связанные уязвимости
CVSS3: 9.8
nvd
почти 6 лет назад
Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based on untrusted user input.