CVE-2021-21315: System Information Library for Node.JS Command Injection.
System Information Library for Node.JS Command Injection. In this vulnerability, an attacker can send a malicious payload that will exploit the name parameter. After successful exploitation, attackers can execute remote.
- CISA KEV-listed (remediation due 2022-02-01)
- EPSS 94.0% (99.9% percentile)