CVE-2022-21165
29.08.2022, 05:15
All versions of package font-converter are vulnerable to Arbitrary Command Injection due to missing sanitization of input that potentially flows into the child_process.exec() function.Enginsight
| Vendor | Product | Version |
|---|---|---|
| font_converter_project | font_converter | 1.0.0 |
| font_converter_project | font_converter | 1.1.0 |
| font_converter_project | font_converter | 1.1.1 |
𝑥
= Vulnerable software versions