CVE-2021-20083
HIGHjquery-plugin-query-object 2.2.3 - Prototype Pollution
Title source: llmDescription
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-plugin-query-object 2.2.3 allows a malicious user to inject properties into Object.prototype.
References (4)
Core 4
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/BlackFan/client-side-prototype-pollution/blob/master/pp/jquery-query-object.md
Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/166299/WordPress-Core-5.9.0-5.9.1-Cross-Site-Scripting.html
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7CR6VGITIB2TXXZ6B5QRRWPU5S4BXQPD/
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IJX6NVXSRN3RX3YUVEJQ4WUTQSDL3DSR/
Scores
CVSS v3
8.8
EPSS
0.0419
EPSS Percentile
89.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-1321
Status
published
Products (2)
jquery-plugin-query-object_project/jquery-plugin-query-object
2.2.3
npm/jquery-query-object
0npm
Published
Apr 23, 2021
Tracked Since
Feb 18, 2026