CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2021-21315

Known Exploited (CISA KEV)HIGH
7.1
CVSS Severity Score
EPSS Score51.7510%
EPSS Percentile91.33th
Published2021年2月16日
Last Modified2025年10月24日

Vulnerability Description

The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 there is a command injection vulnerability. Problem was fixed in version 5.3.1. As a workaround instead of upgrading, be sure to check or sanitize service parameters that are passed to si.inetLatency(), si.inetChecksite(), si.services(), si.processLoad() ... do only allow strings, reject any arrays. String sanitation works as expected.

Affected Platforms (CPE)

📦
Systeminformation

Systeminformation

< 5.3.1
📦
Apache

Cordova

= 10.0.0

References & Advisories

相關漏洞威脅

CVE-2021-21315 Detail & Impact Analysis | CVSS 7.1 (HIGH) | Cyber-Sec.Space | Cyber-Sec.Space