ZeroHour

CVE-2020-7600

PoC
CVSS 3.1
5.3 medium
EPSS
1%p65
Published
()
Modified
Description

querymen prior to 2.1.4 allows modification of object properties. The parameters of exported function handler(type, name, fn) can be controlled by users without any sanitization. This could be abused for Prototype Pollution attacks.

Vendors
querymen project
Products
querymen
Weakness
CWE-1321
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.