CVE-2020-7740
06.10.2020, 18:15
This affects all versions of package node-pdf-generator. Due to lack of user input validation and sanitization done to the content given to node-pdf-generator, it is possible for an attacker to craft a url that will be passed to an external server allowing an SSRF attack.Enginsight
Vendor | Product | Version |
---|---|---|
node-pdf-generator_project | node-pdf-generator | * |
𝑥
= Vulnerable software versions
Common Weakness Enumeration