ZeroHour

CVE-2020-28464

PoC
CVSS 3.1
9.8 critical
EPSS
3%p87
Published
()
Modified
Description

This affects the package djv before 2.1.4. By controlling the schema file, an attacker can run arbitrary JavaScript code on the victim machine.

Vendors
djv project
Products
djv
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.