Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4967
HistoryAug 25, 2017 - 8:56 a.m.

Remote Code Execution (RCE)

2017-08-2508:56:17
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.192 Low

EPSS

Percentile

96.3%

codiad/codiad is vulnerable to remote code execution (RCE) attacks. The library does not properly escape the filepath, allowing a malicious user to inject and execute arbitrary system commands. This CVE is different from CVE-2017-11366 and CVE-2017-15689.

CPENameOperatorVersion
codiad/codiadeq1.3.6