PT-2021-11531 · Unknown · Theme-Core
Published
2021-02-23
·
Updated
2021-07-21
·
CVE-2020-28432
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions:
theme-core versions (affected versions not specified)
Description:
The issue concerns command injection via the lib/utils.js file in the theme-core package. This file is required by the main entry of the package. Technical details include the use of the
sh function within the utils module, which can be exploited. For example, an exploit could involve requiring the theme-core package and then using the utils.sh function to execute system commands, such as creating a file.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Theme-Core