Vulnerability Details CVE-2019-10787
im-resize through 2.3.2 allows remote attackers to execute arbitrary commands via the "exec" argument. The cmd argument used within index.js, can be controlled by user without any sanitization.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.033
EPSS Ranking 86.8%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 10.0
Products affected by CVE-2019-10787
-
cpe:2.3:a:dnt:im-resize:-
-
cpe:2.3:a:dnt:im-resize:1.0.0
-
cpe:2.3:a:dnt:im-resize:1.1.0
-
cpe:2.3:a:dnt:im-resize:2.0.0
-
cpe:2.3:a:dnt:im-resize:2.0.1
-
cpe:2.3:a:dnt:im-resize:2.0.2
-
cpe:2.3:a:dnt:im-resize:2.1.0
-
cpe:2.3:a:dnt:im-resize:2.2.0
-
cpe:2.3:a:dnt:im-resize:2.2.1
-
cpe:2.3:a:dnt:im-resize:2.3.0
-
cpe:2.3:a:dnt:im-resize:2.3.1
-
cpe:2.3:a:dnt:im-resize:2.3.2