CVE-2020-7604 Information
Feb 14, 2021
cve
Description
pulverizr through 0.7.0 allows execution of arbitrary commands. Within \lib/job.js\ the variable \filename\ can be controlled by the attacker. This function uses the variable \filename\ to construct the argument of the exec call without any sanitization. In order to successfully exploit this vulnerability an attacker will need to create a new file with the same name as the attack command.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://snyk.io/vuln/SNYK-JS-PULVERIZR-560122
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: