CVE-2020-28502
05.03.2021, 18:15
This affects the package xmlhttprequest before 1.7.0; all versions of package xmlhttprequest-ssl. Provided requests are sent synchronously (async=False on xhr.open), malicious user input flowing into xhr.send could result in arbitrary code being injected and run.
Vendor | Product | Version |
---|---|---|
xmlhttprequest_project | xmlhttprequest | 𝑥 < 1.7.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
node-xmlhttprequest |
| ||||||||||||||||||||||||
node-xmlhttprequest-ssl |
|
References