Security Advisory

CVE-2023-42810

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-09-21 17:11:54
Last updated 2024-09-24 14:58:02
Assigner GitHub_M
CVSS score 9.8
State PUBLISHED

Description

systeminformation is a System Information Library for Node.JS. Versions 5.0.0 through 5.21.6 have a SSID Command Injection Vulnerability. The problem was fixed with a parameter check in version 5.21.7. As a workaround, check or sanitize parameter strings that are passed to `wifiConnections()`, `wifiNetworks()` (string only).