PT-2020-9154 · Unknown · Serial-Number

Published

2020-02-28

·

Updated

2021-04-13

·

CVE-2019-10804

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions serial-number versions 1.3.0 and earlier
Description The issue allows execution of arbitrary commands. The cmdPrefix argument in the serialNumber function is used by the exec function without any validation.
Recommendations For versions 1.3.0 and earlier, consider disabling the serialNumber function or restricting the use of the cmdPrefix argument until a patch is available. As a temporary workaround, avoid using the exec function with unvalidated input from the serialNumber function.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-10804
GHSA-3FW4-4H3M-892H
SNYK-JS-SERIALNUMBER-559010

Affected Products

Serial-Number