mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-24 11:44:02 +02:00
799 B
799 B
CVE-2019-10787
Description
im-resize through 2.3.2 allows remote attackers to execute arbitrary commands via the "exec" argument. The cmd argument used within index.js, can be controlled by user without any sanitization.
POC
Reference
- https://github.com/Turistforeningen/node-im-resize/commit/de624dacf6a50e39fe3472af1414d44937ce1f03
- https://snyk.io/vuln/SNYK-JS-IMRESIZE-544183
Github
No PoCs found on GitHub currently.