Головна Банки Небанківський фінансовий сектор Кібершахрайство

CVE-2019-10808

utilitify prior to 1.0.3 allows modification of object properties. The merge method could be tricked into adding or modifying properties of the Object.prototype.

    Product

  • xcritical.software utilitify -
  • xcritical.software utilitify 1.0.0
  • xcritical.software utilitify 1.0.1
  • xcritical.software utilitify 1.0.2

Score

6.5

Source

http://nvd.nist.gov

Access-complexity

LOW

Access-vector

NETWORK