What the vulnerability does
01Description
Improper Control of Generation of Code ('Code Injection') vulnerability in NitroPack Inc. NitroPack allows Code Injection.This issue affects NitroPack: from n/a through 1.16.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
What the vulnerability does
Improper Control of Generation of Code ('Code Injection') vulnerability in NitroPack Inc. NitroPack allows Code Injection.This issue affects NitroPack: from n/a through 1.16.7.
Explanation of Vulnerability in Simple Terms
NitroPack versions up to 1.16.7 contain a code injection vulnerability that allows an attacker to inject and execute arbitrary code through a network request. The attack requires specific conditions to be met and does not require authentication or user interaction. This vulnerability can compromise the confidentiality and integrity of data processed by the affected component.
What an attacker can do
Inject and execute arbitrary code on the site through a network request.
Potential impact on your site
An attacker could inject malicious code affecting site data confidentiality and integrity without needing to log in.
Conditions required to exploit
Network access to the site; specific attack conditions must be met (high complexity).
Key dates
External resources
Related vulnerabilities