Vulnerabilities > CVE-2020-7678 - Unspecified vulnerability in Node-Import Project Node-Import
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
This affects all versions of package node-import. The "params" argument of module function can be controlled by users without any sanitization.b. This is then provided to the “eval” function located in line 79 in the index file "index.js".
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |