ZeroHour

CVE-2017-1000228

PoC
CVSS 3.0
9.8 critical
EPSS
6%p93
Published
()
Modified
Description

nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function

Vendors
ejs
Products
ejs
Weakness
CWE-20
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.