CyberRota Analysis
AI analysis pending.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Detected Signals
exploit poc
Note: these links are listed for security research and verification purposes only.
CVE
CVE-2020-28439
Severity
CRITICAL
CVSS
9.8
EPSS
1.57%
Original NVD Description
This affects all versions of package corenlp-js-prefab. The injection point is located in line 10 in 'index.js.' It depends on a vulnerable package 'corenlp-js-interface.' Vulnerability can be exploited with the following PoC: