Описание
Versions of the package window-control before 1.4.5 are vulnerable to Command Injection via the sendKeys function, due to improper input sanitization.
Ссылки
- PatchThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.4.5 (исключая)
cpe:2.3:a:window-control_project:window-control:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 53%
0.00304
Низкий
7.4 High
CVSS3
7.8 High
CVSS3
Дефекты
CWE-78
NVD-CWE-Other
CWE-94
Связанные уязвимости
CVSS3: 7.8
github
около 3 лет назад
window-control vulnerable to Command Injection due to improper input sanitization
EPSS
Процентиль: 53%
0.00304
Низкий
7.4 High
CVSS3
7.8 High
CVSS3
Дефекты
CWE-78
NVD-CWE-Other
CWE-94