ZeroHour

CVE-2017-16020

CVSS 3.1
9.8 critical
EPSS
2%p84
Published
()
Modified
Description

Summit is a node web framework. When using the PouchDB driver in the module, Summit 0.1.0 and later allows an attacker to execute arbitrary commands via the collection name.

Vendors
summit project
Products
summit
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.