Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29231
HistoryFeb 03, 2021 - 7:21 a.m.

Prototype Pollution

2021-02-0307:21:05
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
total.js
prototype pollution
arbitrary properties injection

EPSS

0.006

Percentile

79.0%

total.js is vulnerable to prototype pollution. The keys of the path being set are not properly sanitized, allowing for injection of arbitrary properties into existing construct prototypes and modification of attributes such as __proto__, constructor and prototype.

EPSS

0.006

Percentile

79.0%