← Back to browse · API

CVE-2020-28464

Severity
CRITICAL
CVSS
9.8
EPSS
0.02996
Risk score
40.25
CISA KEV
No
PoC
No
Published
2021-01-04
Modified
2024-09-17
First seen
2026-08-07
Aliases
EUVD-2021-0757, GHSA-4HV7-3Q38-97M8
Products
n/a:djv unspecified <2.1.4
Sources
euvd EUVD-2021-0757

Description

This affects the package djv before 2.1.4. By controlling the schema file, an attacker can run arbitrary JavaScript code on the victim machine.

References