CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Parent: CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

540 vulnerabilities with CWE-1321
CVE-2019-17316 HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Object Injection via Import Module
CVSS 8.8
CVE-2019-17315 HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Object Injection in Administration Module
CVSS 7.2
CVE-2019-16328 HIGH
rpyc 4.1.0-4.1.1 - Remote Code Execution via Prototype Pollution
CVSS 7.5
CVE-2019-10745 HIGH
assign-deep < 0.4.8 - Prototype Pollution via Constructor or __proto__ Payload
CVSS 7.5
CVE-2019-14379 CRITICAL
jackson-databind < 2.9.9.2 - Remote Code Execution via Default Typing with Ehcache
CVSS 9.8
CVE-2019-10744 CRITICAL
lodash < 4.17.12 - Prototype Pollution via defaultsDeep Function
CVSS 9.1
CVE-2019-11358 MEDIUM
jQuery < 3.4.0 - Prototype Pollution via jQuery.extend
CVSS 6.1
CVE-2019-9061 HIGH
CMS Made Simple < 2.2.8 - Authenticated Object Injection via Module Installation
CVSS 8.8
CVE-2019-9058 HIGH
CMS Made Simple < 2.2.8 - Authenticated Object Injection via sel_groups Parameter
CVSS 7.2
CVE-2018-19274 HIGH
phpBB < 3.2.4 - Authenticated Remote Code Execution via Phar Deserialization
CVSS 7.2
CVE-2018-19296 HIGH
PHPMailer <5.2.27, <6.0.6 - Code Injection
CVSS 8.8
CVE-2018-3721 MEDIUM
lodash < 4.17.5 - Prototype Pollution via __proto__ in defaultsDeep, merge, and mergeWith
CVSS 6.5
CVE-2018-11135 HIGH
Quest KACE System Management Appliance 8.0.318 - Authenticated PHP Object Injection via /adminui/error_details.php
CVSS 8.8
CVE-2018-6195 HIGH
Splashing Images < 2.1.1 - Authenticated PHP Object Injection via Session Parameter
CVSS 7.2
CVE-2011-10019 CRITICAL
Spreecommerce < 0.60.2 - Unauthenticated Remote Code Execution via Search Parameter
CVSS 9.8
Details
Vulnerabilities 540