Количество 2
Количество 2
CVE-2019-19609
около 6 лет назад
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Admin panel, because it does not sanitize the plugin name, and attackers can inject arbitrary shell commands to be executed by the execa function.
CVSS3: 7.2
EPSS: Высокий
GHSA-9p2w-rmx4-9mw7
больше 5 лет назад
Command Injection in strapi
CVSS3: 7.2
EPSS: Высокий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2019-19609 The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Admin panel, because it does not sanitize the plugin name, and attackers can inject arbitrary shell commands to be executed by the execa function. | CVSS3: 7.2 | 82% Высокий | около 6 лет назад | |
GHSA-9p2w-rmx4-9mw7 Command Injection in strapi | CVSS3: 7.2 | 82% Высокий | больше 5 лет назад |
Уязвимостей на страницу
20