CVE-2024-36572

9.8CRITICAL

Prototype pollution in allpro form-manager 0.7.4 allows attackers to run arbitrary code and cause other impacts via the functions setDefaults, mergeBranch, and Object.setObjectValue.

Published: 7/30/2024Updated: 11/21/2024

Description

Prototype pollution in allpro form-manager 0.7.4 allows attackers to run arbitrary code and cause other impacts via the functions setDefaults, mergeBranch, and Object.setObjectValue.

AI AnalysisPowered by AI

Affected Products

allproformmanager_data_handler
0.7.4

References