Описание
All versions of the package n158 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports' function.
Note:
To execute the code snippet and potentially exploit the vulnerability, the attacker needs to have the ability to run Node.js code within the target environment. This typically requires some level of access to the system or application hosting the Node.js environment.
Ссылки
- Broken Link
- Third Party Advisory
- Broken Link
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:n158_project:n158:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 37%
0.0016
Низкий
7.8 High
CVSS3
Дефекты
CWE-78
CWE-77
CWE-77
Связанные уязвимости
CVSS3: 7.8
github
больше 2 лет назад
n158 vulnerable to Command Injection due to improper input sanitization in the 'module.exports' function
EPSS
Процентиль: 37%
0.0016
Низкий
7.8 High
CVSS3
Дефекты
CWE-78
CWE-77
CWE-77