Description
Summit is a node web framework. When using the PouchDB driver in the module, Summit 0.1.0 and later allows an attacker to execute arbitrary commands via the collection name.
Remediation
References
https://github.com/notduncansmith/summit/issues/23
https://nodesecurity.io/advisories/315
Related Vulnerabilities
CVE-2022-36045 Vulnerability in npm package nodebb
CVE-2019-10284 Vulnerability in maven package org.jenkins-ci.plugins:diawi-upload
CVE-2022-31367 Vulnerability in npm package strapi
CVE-2022-36094 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates
CVE-2017-18353 Vulnerability in npm package rendertron-middleware