Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Command Injection
Vulnerability Description
This affects all versions of package corenlp-js-prefab. The injection point is located in line 10 in 'index.js.' It depends on a vulnerable package 'corenlp-js-interface.' Vulnerability can be exploited with the following PoC:
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
N/A
Vulnerability Title
Noahdess Corenlp-js-prefab 命令注入漏洞
Vulnerability Description
Noahdess Corenlp-js-prefab是Noahdess个人开发者的一个JS编写的预处理文本数据的代码库。 Noahdess corenlp-js-prefab 存在命令注入漏洞,该漏洞源于注入点位于index.js中的第10行。这取决于一个易受攻击的软件包corenlp-js-interface。
CVSS Information
N/A
Vulnerability Type
N/A