Lucene search

K
cvelistSnykCVELIST:CVE-2020-7600
HistoryMar 12, 2020 - 10:25 p.m.

CVE-2020-7600

2020-03-1222:25:43
snyk
www.cve.org
5

AI Score

5.6

Confidence

High

EPSS

0.001

Percentile

38.8%

querymen prior to 2.1.4 allows modification of object properties. The parameters of exported function handler(type, name, fn) can be controlled by users without any sanitization. This could be abused for Prototype Pollution attacks.

CNA Affected

[
  {
    "product": "querymen",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "All versions prior to 2.1.4"
      }
    ]
  }
]

AI Score

5.6

Confidence

High

EPSS

0.001

Percentile

38.8%

Related for CVELIST:CVE-2020-7600