CVE-2020-7740 Information
Description
This affects all versions of package node-pdf-generator. Due to lack of user input validation and sanitization done to the content given to node-pdf-generator it is possible for an attacker to craft a url that will be passed to an external server allowing an SSRF attack.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Reference
https://github.com/darrenhaken/node-pdf-generator/blob/master/index.js23L29 https://snyk.io/vuln/SNYK-JS-NODEPDFGENERATOR-609636 This affects all versions of package node-pdf-generator. Due to lack of user input validation and sanitization done to the content given to node-pdf-generator it is possible for an attacker to craft a url that will be passed to an external server allowing an SSRF attack.
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
LOW
Base Score
NONE
Base Severity
8.2
Share on: