Описание
Command Injection in tomato
All versions of tomato are vulnerable to Command Injection. The /api/exec endpoint does not validate user input allowing attackers to run arbitrary commands in the system.
Recommendation
No fix is currently available. Consider using an alternative module until a fix is made available.
Пакеты
Наименование
tomato
npm
Затронутые версииВерсия исправления
Отсутствует
Дефекты
CWE-77
Дефекты
CWE-77