Security Advisory

CVE-2020-8132

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-02-28 19:24:41
Last updated 2024-08-04 09:48:25
Assigner hackerone
CVSS score not scored
State PUBLISHED

Description

Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based on untrusted user input.