Vulnerabilities/

Code Injection in cd-messenger

Severity:
High

Description

cd-messenger through 2.7.26 is vulnerable to Arbitrary Code Execution. User input provided to the color argument executed by the eval function resulting in code execution.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
cd-messenger
Anything's wrong? Let us know Last updated on February 01, 2023

This issue is available in SmartScanner Professional

See Pricing