Description
Summit is a node web framework. When using the PouchDB driver in the module, Summit 0.1.0 and later allows an attacker to execute arbitrary commands via the collection name.
Remediation
References
https://github.com/notduncansmith/summit/issues/23
https://nodesecurity.io/advisories/315
Related Vulnerabilities
CVE-2022-31108 Vulnerability in maven package org.webjars.npm:mermaid
CVE-2019-16775 Vulnerability in maven package org.webjars:npm
CVE-2020-13445 Vulnerability in maven package com.liferay:com.liferay.portal.template.freemarker
CVE-2021-3803 Vulnerability in npm package nth-check
CVE-2022-39243 Vulnerability in maven package com.zaxxer:nuprocess