OS Command Injection in GitHub repository jgraph/drawio prior to 21.4.0.
References
Link | Resource |
---|---|
https://github.com/jgraph/drawio/commit/9d6532de36496e77d872d91b1947bb696607d623 | Patch |
https://huntr.dev/bounties/ce75aa04-e4d6-4e0a-9db0-ae84c46ae9e2 | Permissions Required |
Configurations
History
No history.
Information
Published : 2023-07-27 15:15
Updated : 2023-08-03 13:31
NVD link : CVE-2023-3974
Mitre link : CVE-2023-3974
CVE.ORG link : CVE-2023-3974
JSON object : View
Products Affected
diagrams
- drawio
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')