Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25657
HistoryJun 11, 2020 - 7:15 a.m.

Arbitrary Code Execution

2020-06-1107:15:51
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.085 Low

EPSS

Percentile

94.5%

cd-messenger is vulnerable to arbitrary code execution. Untrusted user input to the color argument is passed to the eval function without validation, allowing an attacker to execute arbitrary code.

CPENameOperatorVersion
cd-messengerle2.7.26

0.085 Low

EPSS

Percentile

94.5%

Related for VERACODE:25657