Description
This affects all versions of package corenlp-js-prefab. The injection point is located in line 10 in 'index.js.' It depends on a vulnerable package 'corenlp-js-interface.' Vulnerability can be exploited with the following PoC:
Remediation
References
https://snyk.io/vuln/SNYK-JS-CORENLPJSPREFAB-1050434
Related Vulnerabilities
CVE-2022-28366 Vulnerability in maven package net.sourceforge.htmlunit:neko-htmlunit
CVE-2016-10531 Vulnerability in maven package org.webjars:marked
CVE-2019-3888 Vulnerability in maven package io.undertow:undertow-core
CVE-2016-5016 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-common
CVE-2018-1336 Vulnerability in maven package org.apache.tomcat:tomcat-util