Security Advisory

CVE-2024-39173

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-07-18 00:00:00
Last updated 2024-08-02 04:19:20
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

calculator-boilerplate v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the eval function at /routes/calculator.js. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the input field.