All versions of the package wifey are vulnerable to Command Injection via the connect() function due to improper input sanitization.
References
Link Resource
https://security.snyk.io/vuln/SNYK-JS-WIFEY-3175615 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: snyk

Published: 2023-01-09T05:00:01.045Z

Updated:

Reserved: 2022-02-24T11:58:23.968Z


Link: CVE-2022-25890

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-01-09T05:15:10.917

Modified: 2023-11-07T03:44:52.207


Link: CVE-2022-25890

JSON object: View

cve-icon Redhat Information

No data.