CVE-2020-7678

This affects all versions of package node-import. The "params" argument of module function can be controlled by users without any sanitization.b. This is then provided to the “eval” function located in line 79 in the index file "index.js".
Configurations

Configuration 1 (hide)

cpe:2.3:a:node-import_project:node-import:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2022-07-25 14:15

Updated : 2024-11-21 05:37


NVD link : CVE-2020-7678

Mitre link : CVE-2020-7678

CVE.ORG link : CVE-2020-7678


JSON object : View

Products Affected

node-import_project

  • node-import