@haxtheweb/haxcms-nodejs@11.0.1 vulnerabilities

HAXcms single and multisite nodejs server, api, and administration

  • latest version

    11.0.4

  • latest non vulnerable version

  • first published

    1 years ago

  • latest version published

    27 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @haxtheweb/haxcms-nodejs package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • C
    Command Injection

    @haxtheweb/haxcms-nodejs is a HAXcms nodejs backend

    Affected versions of this package are vulnerable to Command Injection through the gitImportSite functionality which obtains and processes a URL string from a POST request. An attacker can execute arbitrary OS commands on the backend server by crafting a URL that bypasses the insufficient validation checks employed by the filter_var and strpos functions.

    How to fix Command Injection?

    Upgrade @haxtheweb/haxcms-nodejs to version 11.0.3 or higher.

    <11.0.3