Description
This affects all versions of package corenlp-js-prefab. The injection point is located in line 10 in 'index.js.' It depends on a vulnerable package 'corenlp-js-interface.' Vulnerability can be exploited with the following PoC:
Remediation
References
https://snyk.io/vuln/SNYK-JS-CORENLPJSPREFAB-1050434
Related Vulnerabilities
CVE-2019-19771 Vulnerability in npm package bitcoisnj-lib
CVE-2018-16460 Vulnerability in npm package ps
CVE-2022-27340 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2020-6463 Vulnerability in maven package org.webjars.npm:electron
CVE-2023-40351 Vulnerability in maven package org.jenkins-ci.plugins:favorite-view