Description
Summit is a node web framework. When using the PouchDB driver in the module, Summit 0.1.0 and later allows an attacker to execute arbitrary commands via the collection name.
Remediation
References
https://github.com/notduncansmith/summit/issues/23
https://nodesecurity.io/advisories/315
Related Vulnerabilities
CVE-2019-19771 Vulnerability in npm package cionstring
CVE-2018-12541 Vulnerability in maven package io.vertx:vertx-core
CVE-2017-16013 Vulnerability in npm package hapi
CVE-2018-1000620 Vulnerability in maven package org.webjars.npm:cryptiles
CVE-2021-23490 Vulnerability in npm package parse-link-header