CVE-2020-7752

This affects the package systeminformation before 4.27.11. This package is vulnerable to Command Injection. The attacker can concatenate curl's parameters to overwrite Javascript files and then execute any OS commands.
Configurations

Configuration 1

cpe:2.3:a:systeminformation:systeminformation:*:*:*:*:*:node.js:*:*

Information

Published : 2020-10-26 05:15

Updated : 2021-07-21 11:39


NVD link : CVE-2020-7752

Mitre link : CVE-2020-7752

Products Affected
No products.
CWE