Description
The pdfinfojs NPM module versions <= 0.3.6 has a command injection vulnerability that allows an attacker to execute arbitrary commands on the victim's machine.
Remediation
References
https://hackerone.com/reports/330957
Related Vulnerabilities
CVE-2020-13956 Vulnerability in maven package org.apache.httpcomponents:httpclient
CVE-2018-8815 Vulnerability in maven package org.opencms:opencms-core
CVE-2020-8203 Vulnerability in maven package org.fujion.webjars:lodash
CVE-2020-8244 Vulnerability in maven package org.webjars.npm:bl
CVE-2019-5427 Vulnerability in maven package com.mchange:c3p0