CVE-2020-7600 Information

Description

querymen prior to 2.1.4 allows modification of object properties. The parameters of exported function handler(type name fn) can be controlled by users without any sanitization. This could be abused for Prototype Pollution attacks.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Reference

https://github.com/diegohaz/querymen/commit/1987fefcb3b7508253a29502a008d5063a873cef https://snyk.io/vuln/SNYK-JS-QUERYMEN-559867

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

LOW

Base Score

NONE

Base Severity

5.3

Share on: