CVE-2024-36572
9.8CRITICALPrototype pollution in allpro form-manager 0.7.4 allows attackers to run arbitrary code and cause other impacts via the functions setDefaults, mergeBranch, and Object.setObjectValue.
Опубликовано: 7/30/2024Обновлено: 11/21/2024
Описание
Prototype pollution in allpro form-manager 0.7.4 allows attackers to run arbitrary code and cause other impacts via the functions setDefaults, mergeBranch, and Object.setObjectValue.
ИИ-АнализНа базе ИИ
Затронутые продукты
allproformmanager_data_handler
0.7.4
Ссылки
- https://gist.github.com/mestrtee/1771ab4fba733ca898b6e2463dc6ed19Exploit
- https://github.com/allpro/form-manager/issues/1ExploitIssue Tracking
- https://gist.github.com/mestrtee/1771ab4fba733ca898b6e2463dc6ed19Exploit
- https://github.com/allpro/form-manager/issues/1ExploitIssue Tracking