A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input.
References
Link | Resource |
---|---|
https://hackerone.com/reports/703412 | Permissions Required Third Party Advisory |
Configurations
History
29 Oct 2021, 16:13
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://hackerone.com/reports/703412 - Permissions Required, Third Party Advisory |
Information
Published : 2019-12-18 21:15
Updated : 2024-02-04 20:39
NVD link : CVE-2019-15597
Mitre link : CVE-2019-15597
CVE.ORG link : CVE-2019-15597
JSON object : View
Products Affected
node-df_project
- node-df
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')