Description
This affects the package systeminformation before 4.27.11. This package is vulnerable to Command Injection. The attacker can concatenate curl's parameters to overwrite Javascript files and then execute any OS commands.
Remediation
References
https://github.com/sebhildebrandt/systeminformation/blob/master/lib/internet.js
https://github.com/sebhildebrandt/systeminformation/commit/931fecaec2c1a7dcc10457bb8cd552d08089da61
https://snyk.io/vuln/SNYK-JS-SYSTEMINFORMATION-1021909
Related Vulnerabilities
CVE-2018-19907 Vulnerability in maven package org.craftercms:crafter-engine
CVE-2023-45303 Vulnerability in maven package org.thingsboard:thingsboard
CVE-2024-36401 Vulnerability in maven package org.geoserver.web:gs-web-app
CVE-2022-25901 Vulnerability in npm package cookiejar
CVE-2020-35211 Vulnerability in maven package io.atomix:atomix