PT-2021-11531 · Unknown · Theme-Core

Published

2021-02-23

·

Updated

2021-07-21

·

CVE-2020-28432

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions: theme-core versions (affected versions not specified)
Description: The issue concerns command injection via the lib/utils.js file in the theme-core package. This file is required by the main entry of the package. Technical details include the use of the sh function within the utils module, which can be exploited. For example, an exploit could involve requiring the theme-core package and then using the utils.sh function to execute system commands, such as creating a file.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-28432

Affected Products

Theme-Core