CVE-2022-21165
EUVD-2022-655529.08.2022, 05:15
All versions of package font-converter are vulnerable to Arbitrary Command Injection due to missing sanitization of input that potentially flows into the child_process.exec() function.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| font_converter_project | font_converter | 1.0.0 |
| font_converter_project | font_converter | 1.1.0 |
| font_converter_project | font_converter | 1.1.1 |
𝑥
= Vulnerable software versions