PT-2023-22654 · Vconsole · Vconsole

Zer0Dia

·

Published

2023-04-04

·

Updated

2025-02-03

·

CVE-2023-30363

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions vConsole version 3.15.0
Description The issue is related to a prototype pollution in vConsole due to incorrect key and value resolution in the setOptions function in core.ts. This can potentially lead to security issues.
Recommendations For vConsole version 3.15.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Prototype Pollution

Weakness Enumeration

Related Identifiers

BDU:2025-04732
CVE-2023-30363
GHSA-F737-3FH6-JF6W

Affected Products

Vconsole