CVE-2020-28464

Publication date

2021-01-04 11:50:18

Family

snyk

State

PUBLISHED

Description

This affects the package djv before 2.1.4. By controlling the schema file, an attacker can run arbitrary JavaScript code on the victim machine.