Vulnerabilities/

nadesiko3 vulnerable to OS Command Injection

Severity:
High

Description

OS command injection vulnerability in Nako3edit, editor component of nadesiko3 (PC Version) v3.3.74 and earlier allows a remote attacker to obtain appkey of the product and execute an arbitrary OS command on the product.

Recommendation

Update the nadesiko3 package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
nadesiko3
Anything's wrong? Let us know Last updated on January 31, 2023

This issue is available in SmartScanner Professional

See Pricing