PoC Index

CVE-2016-10538

MEDIUM 4.9EPSS 1.0%

The package `node-cli` before 1.0.0 insecurely uses the lock_file and log_file. Both of these are temporary, but it allows the starting user to overwrite any file they have access to.

CVSS v3.0
3.5 LOWCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
CVSS v2.0
4.9 MEDIUMAV:N/AC:M/Au:S/C:N/I:P/A:P
EPSS
0.99% chance of exploitation in the next 30 days, 60th percentile
Published
2018-05-31
Updated
2024-09-17

Proof-of-concept exploits (1)

References

Related