CVE-2020-7678

This affects all versions of package node-import. The "params" argument of module function can be controlled by users without any sanitization.b. This is then provided to the “eval” function located in line 79 in the index file "index.js".
CVSS

No CVSS.

Configurations

No configuration.

Information

Published : 2022-07-25 14:15

Updated : 2022-07-25 15:15


NVD link : CVE-2020-7678

Mitre link : CVE-2020-7678


JSON object : View

Products Affected

No product.

CWE

No CWE.