Vulnerabilities/

Command Injection in wxchangba

Severity:
Medium

Description

All versions of wxchangba are vulnerable to Command Injection. The package does not validate user input on the reqPostMaterial function, passing contents of the file parameter to an exec call. This may allow attackers to run arbitrary commands in the system.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
wxchangba
Anything's wrong? Let us know Last updated on January 09, 2023