ZeroHour

CVE-2020-28447

PoC
CVSS 3.1
9.8 critical
EPSS
1%p68
Published
()
Modified
Description

This affects all versions of package xopen. The injection point is located in line 14 in index.js in the exported function xopen(filepath)

Vendors
xopen project
Products
xopen
Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.