A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input.
References
Link | Resource |
---|---|
https://hackerone.com/reports/703412 | Permissions Required Third Party Advisory |
https://hackerone.com/reports/703412 | Permissions Required Third Party Advisory |
Configurations
History
21 Nov 2024, 04:29
Type | Values Removed | Values Added |
---|---|---|
References | () https://hackerone.com/reports/703412 - Permissions Required, Third Party Advisory |
Information
Published : 2019-12-18 21:15
Updated : 2024-11-21 04:29
NVD link : CVE-2019-15597
Mitre link : CVE-2019-15597
CVE.ORG link : CVE-2019-15597
JSON object : View
Products Affected
node-df_project
- node-df
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')