CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Parent: CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

501 vulnerabilities with CWE-1321
CVE-2020-7608 MEDIUM
yargs-parser < 5.0.1 and 6.0.0-13.1.2 - Prototype Pollution via __proto__ Payload
CVSS 5.3
CVE-2020-7600 MEDIUM
querymen < 2.1.4 - Prototype Pollution via Unsanitized Handler Parameters
CVSS 5.3
CVE-2020-7598 MEDIUM
minimist < 1.2.2 - Prototype Pollution via Constructor or __proto__ Payload
CVSS 5.6
CVE-2020-5258 HIGH
dojo < 1.11.10 - Prototype Pollution via deepCopy Method
CVSS 7.7
CVE-2020-8116 HIGH
dot-prop <4.2.1, <5.1.1 - Prototype Pollution
CVSS 7.3
CVE-2019-0230 CRITICAL
Apache Struts 2.0.0-2.5.20 - Remote Code Execution via Forced Double OGNL Evaluation
CVSS 9.8
CVE-2019-10808 HIGH
utilitify < 1.0.3 - Prototype Pollution via Merge Method
CVSS 8.8
CVE-2019-10806 MEDIUM
vega < 1.13.1 - Prototype Pollution via vega.mergeConfig
CVSS 4.3
CVE-2019-19919 CRITICAL
handlebars.js - Prototype Pollution leading to Remote Code Execution
CVSS 9.8
CVE-2019-10768 HIGH
AngularJS < 1.7.9 - Prototype Pollution via merge() Function
CVSS 7.5
CVE-2019-17317 HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Object Injection via UpgradeWizard Module
CVSS 7.2
CVE-2019-17316 HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Object Injection via Import Module
CVSS 8.8
CVE-2019-17315 HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Object Injection in Administration Module
CVSS 7.2
CVE-2019-16328 HIGH
rpyc 4.1.0-4.1.1 - Remote Code Execution via Prototype Pollution
CVSS 7.5
CVE-2019-10745 HIGH
assign-deep < 0.4.8 - Prototype Pollution via Constructor or __proto__ Payload
CVSS 7.5
CVE-2019-14379 CRITICAL
jackson-databind < 2.9.9.2 - Remote Code Execution via Default Typing with Ehcache
CVSS 9.8
CVE-2019-10744 CRITICAL
lodash < 4.17.12 - Prototype Pollution via defaultsDeep Function
CVSS 9.1
CVE-2019-11358 MEDIUM
jQuery < 3.4.0 - Prototype Pollution via jQuery.extend
CVSS 6.1
CVE-2019-9061 HIGH
CMS Made Simple < 2.2.8 - Authenticated Object Injection via Module Installation
CVSS 8.8
CVE-2019-9058 HIGH
CMS Made Simple < 2.2.8 - Authenticated Object Injection via sel_groups Parameter
CVSS 7.2
CVE-2018-19274 HIGH
phpBB < 3.2.4 - Authenticated Remote Code Execution via Phar Deserialization
CVSS 7.2
CVE-2018-19296 HIGH
PHPMailer <5.2.27, <6.0.6 - Code Injection
CVSS 8.8
CVE-2018-3721 MEDIUM
lodash < 4.17.5 - Prototype Pollution via __proto__ in defaultsDeep, merge, and mergeWith
CVSS 6.5
CVE-2018-11135 HIGH
Quest KACE System Management Appliance 8.0.318 - Authenticated PHP Object Injection via /adminui/error_details.php
CVSS 8.8
CVE-2018-6195 HIGH
Splashing Images < 2.1.1 - Authenticated PHP Object Injection via Session Parameter
CVSS 7.2
Details
Vulnerabilities 501