ZeroHour

CVE-2019-10789

PoC ×2
CVSS 3.1
9.8 critical
EPSS
5%p92
Published
()
Modified
Description

All versions of curling.js are vulnerable to Command Injection via the run function. The command argument can be controlled by users without any sanitization.

Vendors
curling project
Products
curling
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.