Description
pixl-class prior to 1.0.3 allows execution of arbitrary commands. The members argument of the create function can be controlled by users without any sanitization.
Remediation
References
https://github.com/jhuckaby/pixl-class/commit/47677a3638e3583e42f3a05cc7f0b30293d2acc8
https://snyk.io/vuln/SNYK-JS-PIXLCLASS-564968
https://github.com/jhuckaby/pixl-class/commit/47677a3638e3583e42f3a05cc7f0b30293d2acc8%2C
Related Vulnerabilities
CVE-2022-41642 Vulnerability in npm package nadesiko3
CVE-2017-10355 Vulnerability in maven package xerces:xercesimpl
CVE-2020-13822 Vulnerability in npm package elliptic
CVE-2018-14042 Vulnerability in maven package org.webjars.bowergithub.angular-ui:bootstrap
CVE-2021-33561 Vulnerability in maven package com.shopizer:shopizer