Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38373
HistoryDec 08, 2022 - 6:24 a.m.

OS Command Injection

2022-12-0806:24:12
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
os command injection
nadesiko3
index.mjs
appkey validation
arbitrary commands

EPSS

0.005

Percentile

77.8%

nadesiko3 is vulnerable to os command injection. The vulnerability exists in multiple functions in index.mjs because appkey is not properly validated which allows an attacker to inject and execute arbitrary commands into the system via the file parameter.

EPSS

0.005

Percentile

77.8%

Related for VERACODE:38373