Description
This affects all versions up to and including version 0.0.24 of package mock2easy. a malicious user could inject commands through the _data variable:
Affected Area
Recommendation
No fix is available yet. Followings are affected versions:
- <= 0.0.24
References
Related Issues
- Code Injection in node-rules - CVE-2020-7609
- Code Injection in mosc - CVE-2020-7672
- xmlhttprequest and xmlhttprequest-ssl vulnerable to Arbitrary Code Injection - xmlhttprequest - CVE-2020-28502
- xmlhttprequest and xmlhttprequest-ssl vulnerable to Arbitrary Code Injection - CVE-2020-28502
You might also like:
- Tags:
- npm
- mock2easy
Anything's wrong? Let us know Last updated on September 08, 2023


