This affects all versions of package node-import. The "params" argument of module function can be controlled by users without any sanitization.b. This is then provided to the eval function located ...
Continue ReadingJuly 25, 2022
This affects the package snyk-broker before 4.73.0. It allows arbitrary file reads for users with access to Snyk's internal network via directory traversal.Read More ...
Continue ReadingJuly 25, 2022
This affects all versions of package ion-parser. If an attacker submits a malicious INI file to an application that parses it with parse , they will pollute the prototype on the application. This can ...
Continue ReadingJuly 25, 2022
This affects the package js-ini before 1.3.0. If an attacker submits a malicious INI file to an application that parses it with parse , they will pollute the prototype on the application. This can be ...
Continue ReadingJuly 25, 2022
This affects all versions of package xopen. The injection point is located in line 14 in index.js in the exported function xopen(filepath)Read More ...
Continue ReadingJuly 25, 2022
This affects all versions of package markdown-it-toc. The title of the generated toc and the contents of the header are not escaped.Read More ...
Continue ReadingJuly 25, 2022
This affects all versions of package npm-help. The injection point is located in line 13 in index.js file in export.latestVersion() function.Read More ...
Continue ReadingJuly 25, 2022
A vulnerability exists in the HTTP web interface where the web interface does not sufficiently verify if a well-formed, valid, consistent request was intentionally provided by the user who submitted t ...
Continue ReadingJuly 25, 2022
Back to Main