VYPR

Textract

by Textract Project

CVEs (1)

  • CVE-2016-10320HigApr 6, 2017
    risk 0.51cvss 7.8epss 0.01

    textract before 1.5.0 allows OS Command Injection attacks via a filename in a call to the process function. This may be a remote attack if a web application accepts names of arbitrary uploaded files.