CVE-2020-7752

HIGH

Systeminformation < 4.27.11 - OS Command Injection

Title source: rule
STIX 2.1

Description

This affects the package systeminformation before 4.27.11. This package is vulnerable to Command Injection. The attacker can concatenate curl's parameters to overwrite Javascript files and then execute any OS commands.

References (3)

Core 3

Scores

CVSS v3 8.8
EPSS 0.0314
EPSS Percentile 87.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (2)
npm/systeminformation 0 - 4.27.11npm
systeminformation/systeminformation < 4.27.11
Published Oct 26, 2020
Tracked Since Feb 18, 2026