wxchangba@1.0.3 vulnerabilities

微信唱吧: 基于node.js和微信jssdk的校园轻应用

Direct Vulnerabilities

Known vulnerabilities in the wxchangba package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Arbitrary Code Injection

wxchangba is a Campus light application based on node.js and WeChat jssdk.

Affected versions of this package are vulnerable to Arbitrary Code Injection. The package does not validate user input for the reqPostMaterial function, thereby passing unsanitized contents of the file parameter to an exec call. This could potentially allow attackers to run arbitrary commands in the system.

How to fix Arbitrary Code Injection?

There is no fixed version for wxchangba.

*