CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
540 vulnerabilities with CWE-1321
CVE-2019-17316
HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Object Injection via Import Module
CVSS 8.8
CVE-2019-17315
HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Object Injection in Administration Module
CVSS 7.2
CVE-2019-16328
HIGH
rpyc 4.1.0-4.1.1 - Remote Code Execution via Prototype Pollution
CVSS 7.5
CVE-2019-10745
HIGH
assign-deep < 0.4.8 - Prototype Pollution via Constructor or __proto__ Payload
CVSS 7.5
CVE-2019-14379
CRITICAL
jackson-databind < 2.9.9.2 - Remote Code Execution via Default Typing with Ehcache
CVSS 9.8
CVE-2019-10744
CRITICAL
lodash < 4.17.12 - Prototype Pollution via defaultsDeep Function
CVSS 9.1
CVE-2019-11358
MEDIUM
jQuery < 3.4.0 - Prototype Pollution via jQuery.extend
CVSS 6.1
CVE-2019-9061
HIGH
CMS Made Simple < 2.2.8 - Authenticated Object Injection via Module Installation
CVSS 8.8
CVE-2019-9058
HIGH
CMS Made Simple < 2.2.8 - Authenticated Object Injection via sel_groups Parameter
CVSS 7.2
CVE-2018-19274
HIGH
phpBB < 3.2.4 - Authenticated Remote Code Execution via Phar Deserialization
CVSS 7.2
CVE-2018-19296
HIGH
PHPMailer <5.2.27, <6.0.6 - Code Injection
CVSS 8.8
CVE-2018-3721
MEDIUM
lodash < 4.17.5 - Prototype Pollution via __proto__ in defaultsDeep, merge, and mergeWith
CVSS 6.5
CVE-2018-11135
HIGH
Quest KACE System Management Appliance 8.0.318 - Authenticated PHP Object Injection via /adminui/error_details.php
CVSS 8.8
CVE-2018-6195
HIGH
Splashing Images < 2.1.1 - Authenticated PHP Object Injection via Session Parameter
CVSS 7.2
CVE-2011-10019
CRITICAL
Spreecommerce < 0.60.2 - Unauthenticated Remote Code Execution via Search Parameter
CVSS 9.8
Details
Vulnerabilities
540