
We found results for “”
WS-2019-0131
Good to know:

Date: June 11, 2019
expressfs does not validate user input on several API endpoints, allowing attackers to run arbitrary commands in the system. this command injection vulnerability exist in all versions
Language: JS
Severity Score
Related Resources (2)
Severity Score
Weakness Type (CWE)
Top Fix

CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | HIGH |