CVE-2021-21315

System Information Library for Node.JS Command Injection

In this vulnerability, an attacker can send a malicious payload that will exploit the name parameter. After successful exploitation, attackers can execute remote. Vendor/Product: Npm package System Information Library for Node.JS. Added to CISA KEV 2022-01-18; required action: Apply updates per vendor instructions.

Category: Vulnerability, Known Exploited