Описание
A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input.
Ссылки
- Permissions RequiredThird Party Advisory
- Permissions RequiredThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:node-df_project:node-df:0.1.4:*:*:*:*:node.js:*:*
EPSS
Процентиль: 88%
0.03754
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-94
CWE-94
Связанные уязвимости
CVSS3: 8.8
redhat
около 6 лет назад
A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input.
EPSS
Процентиль: 88%
0.03754
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-94
CWE-94