A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input.
References
Link | Resource |
---|---|
https://hackerone.com/reports/703412 | Permissions Required Third Party Advisory |
Configurations
Information
Published : 2019-12-18 13:15
Updated : 2021-10-29 09:13
NVD link : CVE-2019-15597
Mitre link : CVE-2019-15597
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
node-df_project
- node-df