CVE-2024-39173

July 18, 2024, 8:15 p.m.

Received
CVE has been recently published to the CVE List and has been received by the NVD.

Products

calculator-boilerplate

  • 1.0

Source

cve@mitre.org

Tags

CVE-2024-39173 details

Published : July 18, 2024, 8:15 p.m.
Last Modified : July 18, 2024, 8:15 p.m.

Description

calculator-boilerplate v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the eval function at /routes/calculator.js. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the input field.

CVSS Score

1 2 3 4 5 6 7 8 9 10

Weakness

Weakness Name Description

References

URL Source
http://kropov.com/calculator-boilerplate-cve.txt cve@mitre.org
This website uses the NVD API, but is not approved or certified by it.