First published: Thu Nov 26 2020(Updated: )
This affects the package systeminformation before 4.30.2. The attacker can overwrite the properties and functions of an object, which can lead to executing OS commands.
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
Systeminformation Systeminformation Node.js | <4.30.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-7778 is a vulnerability in the systeminformation package before version 4.30.2 that allows an attacker to overwrite object properties and functions, potentially leading to the execution of OS commands.
The systeminformation package before version 4.30.2 is affected by CVE-2020-7778.
CVE-2020-7778 has a severity score of 7.3 (high).
CVE-2020-7778 can be exploited by an attacker overwriting the properties and functions of an object.
To fix CVE-2020-7778, update the systeminformation package to version 4.30.2 or later.