Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Command Injection
Vulnerability Description
This affects the package madge before 4.0.1. It is possible to specify a custom Graphviz path via the graphVizPath option parameter which when the .image(), .svg() or .dot() functions are called, is executed by the childprocess.exec function.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Vulnerability Type
N/A
Vulnerability Title
madge SQL注入漏洞
Vulnerability Description
madge是开源的一个开发者工具,用于生成模块依赖关系的可视化图表,查找循环依赖关系,并为您提供其他有用的信息。 madge before 4.0.1 存在SQL注入漏洞,该漏洞源于graphVizPath选项参数指定一个自定义的Graphviz路径,当调用image()、svg()或.ot()函数时,该路径由childprocess.exec函数。
CVSS Information
N/A
Vulnerability Type
N/A