CVE-2024-39173
July 18, 2024, 8:15 p.m.
Tags
Product(s) Impacted
calculator-boilerplate
- 1.0
Description
calculator-boilerplate v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the eval function at /routes/calculator.js. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the input field.
Weaknesses
Date
Published: July 18, 2024, 8:15 p.m.
Last Modified: July 18, 2024, 8:15 p.m.
Status : Received
CVE has been recently published to the CVE List and has been received by the NVD.
More infoSource
cve@mitre.org
References
http://kropov.com/
cve@mitre.org