ZeroHour

CVE-2019-10783

PoC
CVSS 3.1
9.8 critical
EPSS
3%p85
Published
()
Modified
Description

All versions including 0.0.4 of lsof npm module are vulnerable to Command Injection. Every exported method used by the package uses the exec function to parse user input.

Vendors
isof project
Products
isof
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.