PT-2022-17578 · Querymen · Querymen

Abdullah Alhamdan

+1

·

Published

2022-06-17

·

Updated

2022-06-28

·

CVE-2022-25871

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions querymen (affected versions not specified)
Description The issue arises from the handler(type, name, fn) function, where the parameters can be controlled by users without proper sanitization, leading to Prototype Pollution. This is a result of an incomplete fix of a previous issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-25871
GHSA-P23C-P8W2-WW5V
SNYK-JS-QUERYMEN-2391488

Affected Products

Querymen