CVE-2021-23374 is a critical command injection vulnerability affecting all versions of the ps-visitor package. It allows unauthenticated attackers to execute arbitrary commands on a vulnerable system by providing malicious input to the 'kill' function, due to improper input sanitization within the 'child_process exec' function. This vulnerability carries a CVSS score of 9.8 (Critical), indicating a severe risk with no user interaction required and complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation (KEV, Hot List inactive) and no public exploit modules (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion, suggesting awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:ps-visitor_project:ps-visitor:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.