CVE-2019-10805
28.02.2020, 21:15
valib through 2.0.0 allows Internal Property Tampering. A maliciously crafted JavaScript object can bypass several inspection functions provided by valib. Valib uses a built-in function (hasOwnProperty) from the unsafe user-input to examine an object. It is possible for a crafted payload to overwrite this function to manipulate the inspection results to bypass security checks.Enginsight
Vendor | Product | Version |
---|---|---|
sideralis | valib.js | 𝑥 ≤ 2.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration