PT-2020-19647 · Querymen · Querymen
Published
2020-03-12
·
Updated
2022-12-02
·
CVE-2020-7600
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
querymen versions prior to 2.1.4
Description
The issue allows modification of object properties due to a lack of sanitization in the parameters of the exported function
handler(type, name, fn), which can be controlled by users. This could be abused for Prototype Pollution attacks.Recommendations
For versions prior to 2.1.4, update to version 2.1.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the
handler() function to minimize the risk of exploitation. Avoid using the type, name, and fn parameters in the affected function until the issue is resolved.Exploit
Fix
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Querymen