Description
wifiscanner.js in thingsSDK WiFi Scanner 1.0.1 allows Code Injection because it can be used with options to overwrite the default executable/binary path and its arguments. An attacker can abuse this functionality to execute arbitrary code.
Remediation
References
https://github.com/thingsSDK/wifiscanner/issues/1
Related Vulnerabilities
CVE-2021-23374 Vulnerability in npm package ps-visitor
CVE-2019-1010266 Vulnerability in maven package org.webjars.bower:lodash
CVE-2021-24033 Vulnerability in npm package react-dev-utils
CVE-2024-1597 Vulnerability in maven package org.postgresql:postgresql
CVE-2022-29251 Vulnerability in maven package org.xwiki.platform:xwiki-platform-flamingo-theme-ui