CVE-2019-10778
08.01.2020, 16:15
devcert-sanscache before 0.4.7 allows remote attackers to execute arbitrary code or cause a Command Injection via the exec function. The variable `commonName` controlled by user input is used as part of the `exec` function without any sanitization.
Vendor | Product | Version |
---|---|---|
devcert-sanscache_project | devcert-sanscache | 𝑥 < 0.4.7 |
𝑥
= Vulnerable software versions