Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38344
HistoryDec 05, 2022 - 6:09 p.m.

Remote Code Execution (RCE)

2022-12-0518:09:51
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7
mujs
remote code execution
vulnerability
o_getownpropertydescriptor
memory corruption
crafted javascript file

EPSS

0.015

Percentile

87.2%

mujs is vulnerable to remote code execution. The vulnerability exists due to the logical issue in the O_getOwnPropertyDescriptor function, allowing an attacker to inject and execute malicious code through memory corruption via the loading of a crafted javascript file.