An attacker can use the format parameter to inject arbitrary commands in the npm package morgan < 1.9.1.
References
Configurations
History
No history.
Information
Published : 2019-03-21 16:01
Updated : 2023-11-07 03:11
NVD link : CVE-2019-5413
Mitre link : CVE-2019-5413
CVE.ORG link : CVE-2019-5413
JSON object : View
Products Affected
morgan_project
- morgan