CVE-2024-39173
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/07/2024
Last modified:
01/08/2024
Description
calculator-boilerplate v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the eval function at /routes/calculator.js. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the input field.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL



