PT-2020-9151 · Enpeem · Enpeem

Published

2020-02-28

·

Updated

2021-04-13

·

CVE-2019-10801

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions enpeem versions 2.2.0 and earlier
Description The issue allows execution of arbitrary commands. The options.dir argument is provided to the exec function without any sanitization.
Recommendations For versions 2.2.0 and earlier, as a temporary workaround, consider disabling the exec function until a patch is available. Restrict access to the options.dir argument to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-10801
GHSA-HMW2-MVVH-JF5J
SNYK-JS-ENPEEM-559007

Affected Products

Enpeem