Description
This affects the package connection-tester before 0.2.1. The injection point is located in line 15 in index.js. The following PoC demonstrates the vulnerability:
Remediation
References
https://github.com/skoranga/node-connection-tester/pull/10
https://snyk.io/vuln/SNYK-JS-CONNECTIONTESTER-1048337
Related Vulnerabilities
CVE-2020-7746 Vulnerability in maven package org.webjars.bower:chart.js
CVE-2022-25967 Vulnerability in npm package eta
CVE-2022-1365 Vulnerability in npm package cross-fetch
CVE-2021-23771 Vulnerability in npm package argencoders-notevil
CVE-2021-22569 Vulnerability in maven package com.google.protobuf:protobuf-java