ZeroHour

CVE-2019-10787

PoC
CVSS 3.1
9.8 critical
EPSS
4%p89
Published
()
Modified
Description

im-resize through 2.3.2 allows remote attackers to execute arbitrary commands via the "exec" argument. The cmd argument used within index.js, can be controlled by user without any sanitization.

Vendors
dnt
Products
im-resize
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.