{"id":"GHSA-h86x-mv66-gr5q","summary":"OS Command Injection in Locutus","details":"php/exec/escapeshellarg in Locutus PHP through 2.0.11 allows an attacker to achieve code execution.","aliases":["CVE-2020-13619"],"modified":"2023-11-08T04:02:19.966657Z","published":"2021-07-26T21:21:43Z","database_specific":{"nvd_published_at":"2020-07-01T17:15:00Z","cwe_ids":["CWE-78"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2021-07-26T19:28:18Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-13619"},{"type":"WEB","url":"https://locutus.io/php"},{"type":"WEB","url":"https://web.archive.org/web/20230521185837/https://reallinkers.github.io/CVE-2020-13619"},{"type":"WEB","url":"https://www.npmjs.com/package/locutus"}],"affected":[{"package":{"name":"locutus","ecosystem":"npm","purl":"pkg:npm/locutus"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"2.0.11"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/07/GHSA-h86x-mv66-gr5q/GHSA-h86x-mv66-gr5q.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}