Логотип exploitDog
bind:CVE-2020-6836
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-6836

Количество 2

Количество 2

nvd логотип

CVE-2020-6836

около 6 лет назад

grammar-parser.jison in the hot-formula-parser package before 3.0.1 for Node.js is vulnerable to arbitrary code injection. The package fails to sanitize values passed to the parse function and concatenates them in an eval call. If a value of the formula is taken from user-controlled input, it may allow attackers to run arbitrary commands on the server.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-rc77-xxq6-4mff

почти 6 лет назад

Command Injection in hot-formula-parser

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-6836

grammar-parser.jison in the hot-formula-parser package before 3.0.1 for Node.js is vulnerable to arbitrary code injection. The package fails to sanitize values passed to the parse function and concatenates them in an eval call. If a value of the formula is taken from user-controlled input, it may allow attackers to run arbitrary commands on the server.

CVSS3: 9.8
1%
Низкий
около 6 лет назад
github логотип
GHSA-rc77-xxq6-4mff

Command Injection in hot-formula-parser

CVSS3: 9.8
1%
Низкий
почти 6 лет назад

Уязвимостей на страницу