Description
Summit is a node web framework. When using the PouchDB driver in the module, Summit 0.1.0 and later allows an attacker to execute arbitrary commands via the collection name.
Remediation
References
https://github.com/notduncansmith/summit/issues/23
https://nodesecurity.io/advisories/315
Related Vulnerabilities
CVE-2023-4316 Vulnerability in npm package zod
CVE-2018-19413 Vulnerability in maven package org.sonarsource.sonarqube:sonar-plugin-api
CVE-2020-24025 Vulnerability in maven package org.webjars.npm:node-sass
CVE-2020-36379 Vulnerability in npm package aaptjs
CVE-2023-22467 Vulnerability in maven package org.webjars.bowergithub.moment:luxon