Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29225
HistoryFeb 03, 2021 - 5:11 a.m.

OS Command Injection

2021-02-0305:11:41
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
total.js
os command injection
unvalidated parameter

EPSS

0.004

Percentile

73.4%

total.js is vulnerable to OS command injection. The type parameter is not properly sanitized and validated, and is used to build the command which is subsequently executed using child_process.spawn.

EPSS

0.004

Percentile

73.4%