ZeroHour

CVE-2018-13797

PoC
CVSS 3.0
9.8 critical
EPSS
7%p93
Published
()
Modified
Description

The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.

Vendors
node-macaddress project
Products
node-macaddress
Weakness
CWE-78
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.