Количество 2
Количество 2
CVE-2019-10805
valib through 2.0.0 allows Internal Property Tampering. A maliciously crafted JavaScript object can bypass several inspection functions provided by valib. Valib uses a built-in function (hasOwnProperty) from the unsafe user-input to examine an object. It is possible for a crafted payload to overwrite this function to manipulate the inspection results to bypass security checks.
GHSA-pmpr-vc5q-h3jw
Exposure of Resource to Wrong Sphere in valib
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2019-10805 valib through 2.0.0 allows Internal Property Tampering. A maliciously crafted JavaScript object can bypass several inspection functions provided by valib. Valib uses a built-in function (hasOwnProperty) from the unsafe user-input to examine an object. It is possible for a crafted payload to overwrite this function to manipulate the inspection results to bypass security checks. | CVSS3: 7.5 | 0% Низкий | почти 6 лет назад | |
GHSA-pmpr-vc5q-h3jw Exposure of Resource to Wrong Sphere in valib | CVSS3: 7.5 | 0% Низкий | почти 5 лет назад |
Уязвимостей на страницу