Severity | High |
Patch available | YES |
Number of vulnerabilities | 2 |
CVE ID | N/A |
CWE ID | CWE-94 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software Subscribe |
dotty Web applications / Modules and components for CMS dotty Web applications / Modules and components for CMS |
Vendor | NextAuth.js |
Severity: High
CVE-ID: N/A
CWE-ID:
CWE-94 - Improper Control of Generation of Code ('Code Injection')
dotty: 0.0.1, 0.0.2, 0.0.3, 0.1.0
CPEhttps://www.npmjs.com/advisories/1620
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
Severity: High
CVE-ID: N/A
CWE-ID:
CWE-94 - Improper Control of Generation of Code ('Code Injection')
dotty: 0.0.1, 0.0.2, 0.0.3, 0.1.0
CPEhttps://www.npmjs.com/advisories/1620
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.