Описание
This affects the package systeminformation before 4.30.2. The attacker can overwrite the properties and functions of an object, which can lead to executing OS commands.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.30.2 (исключая)
cpe:2.3:a:systeminformation:systeminformation:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 78%
0.01103
Низкий
7.3 High
CVSS3
7.5 High
CVSS2
Дефекты
CWE-78
Связанные уязвимости
EPSS
Процентиль: 78%
0.01103
Низкий
7.3 High
CVSS3
7.5 High
CVSS2
Дефекты
CWE-78