CVE Database
/

CVE-2020-7600

Back to search

CVE-2020-7600

Published: Mar 12, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

querymen prior to 2.1.4 allows modification of object properties. The parameters of exported function handler(type, name, fn) can be controlled by users without any sanitization. This could be abused for Prototype Pollution attacks.

VendorProductVersions

n/a

querymen

affected
All versions prior to 2.1.4

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now