9.8
CVSSv3

CVE-2020-6836

Published: 11/01/2020 Updated: 22/01/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

grammar-parser.jison in the hot-formula-parser package prior to 3.0.1 for Node.js is vulnerable to arbitrary code injection. The package fails to sanitize values passed to the parse function and concatenates them in an eval call. If a value of the formula is taken from user-controlled input, it may allow malicious users to run arbitrary commands on the server.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hot-formula-parser project hot-formula-parser