Description
This affects the package systeminformation before 4.27.11. This package is vulnerable to Command Injection. The attacker can concatenate curl's parameters to overwrite Javascript files and then execute any OS commands.
Remediation
References
https://github.com/sebhildebrandt/systeminformation/blob/master/lib/internet.js
https://github.com/sebhildebrandt/systeminformation/commit/931fecaec2c1a7dcc10457bb8cd552d08089da61
https://snyk.io/vuln/SNYK-JS-SYSTEMINFORMATION-1021909
Related Vulnerabilities
CVE-2023-34610 Vulnerability in maven package com.cedarsoftware:json-io
CVE-2021-34084 Vulnerability in npm package s3-uploader
CVE-2021-44878 Vulnerability in maven package org.pac4j:pac4j-core
CVE-2021-30109 Vulnerability in npm package froala-editor
CVE-2022-47105 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base-core