Security Advisory
CVE-2020-28439
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
This affects all versions of package corenlp-js-prefab. The injection point is located in line 10 in index.js. It depends on a vulnerable package corenlp-js-interface. Vulnerability can be exploited with the following PoC: