This affects the package systeminformation before 4.27.11. This package is vulnerable to Command Injection. The attacker can concatenate curl's parameters to overwrite Javascript files and then execute any OS commands.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: snyk

Published: 2020-10-26T00:00:00

Updated: 2020-10-26T17:12:31

Reserved: 2020-01-21T00:00:00


Link: CVE-2020-7752

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-10-26T17:15:12.987

Modified: 2021-07-21T11:39:23.747


Link: CVE-2020-7752

JSON object: View

cve-icon Redhat Information

No data.

CWE