Vulnerabilities
8 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-28461 | This affects the package js-ini before 1.3.0. This affects the package js-ini before 1.3.0. If an attacker submits a malicious INI file to an application that parses it with parse , they will pollute the prototype on the application. This can be exploited further depending on the context. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2020-28441 | This affects the package conf-cfg-ini before 1.2.2. This affects the package conf-cfg-ini before 1.2.2. If an attacker submits a malicious INI file to an application that parses it with decode, they will pollute the prototype on the application. This can be exploited further depending on the context. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2020-18999 +1 in the same advisory: …18998 | Cross Site Scripting (XSS) in Blog_mini v1.0 allows remote attackers to execute arbitrary code via the component '/admin/submit-articles'. Cross Site Scripting (XSS) in Blog_mini v1.0 allows remote attackers to execute arbitrary code via the component '/admin/submit-articles'. NVD description · AI analysis pending | 6.1 | 1% | PoC |
| — | |
| CVE-2020-28448 +1 in the same advisory: …28460 | This affects the package multi-ini before 2.1.1. This affects the package multi-ini before 2.1.1. It is possible to pollute an object's prototype by specifying the proto object as part of an array. NVD description · AI analysis pending | 9.8 group max | 1% | PoC ×2 |
| — | |
| CVE-2020-7788 | This affects the package ini before 1.3.6. This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context. NVD description · AI analysis pending | 9.8 | 4% | PoC |
| — | |
| CVE-2019-9765 | In Blog_mini 1.0, XSS exists via the author name of a comment reply in the app/main/views.py articleDetails() function, related to app/templates/_article_commen In Blog_mini 1.0, XSS exists via the author name of a comment reply in the app/main/views.py articleDetails() function, related to app/templates/_article_comments.html. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — |