Lucene search

K
nodejsCaio LรผdersNODEJS:643
HistoryMay 16, 2018 - 4:01 p.m.

Command Injection

2018-05-1616:01:00
Caio Lรผders
www.npmjs.com
505

0.004 Low

EPSS

Percentile

72.4%

Overview

Versions of pdfinfojs before 0.4.1 are vulnerable to command injection. This is exploitable if an attacker can control the filename parameter that is passed into the pdfinfojs constructor.

Recommendation

Update to version 0.4.1 or later.

References

CPENameOperatorVersion
pdfinfojsle0.4.0

0.004 Low

EPSS

Percentile

72.4%