PT-2017-10977 · Mathjs · Math.Js

Xfix

·

Published

2017-11-27

·

Updated

2019-10-09

·

CVE-2017-1001003

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions math.js versions prior to 3.17.0
Description The issue allows private properties, such as a constructor, to be replaced by utilizing unicode characters when creating an object.
Recommendations For math.js versions prior to 3.17.0, upgrade to version 3.17.0 or later.

Fix

Argument Injection

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-1001003
GHSA-PV8X-P9HQ-J328

Affected Products

Math.Js