n0npax

1 exploit Active since Dec 2020
CVE-2020-35669 NOMISEC MEDIUM WORKING POC
dart/http < 0.12.2 and Pub/http < 0.13.3 - CRLF Injection via HTTP Method
An issue was discovered in the http package through 0.12.2 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request.
1 stars
CVSS 6.1