GHSA-866w-xmhq-wj7x
ADVISORY - githubSummary
If you use remote form functions, have an input field of type file, and accept arbitrary user-controlled path names for the field, then you are vulnerable to a prototype pollution attack where the attacker can remove e.g. methods on the prototype.
Common Weakness Enumeration (CWE)
ADVISORY - github
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
GitHub
CREATED
UPDATED
ADVISORY IDGHSA-866w-xmhq-wj7x
EXPLOITABILITY SCORE
2.8
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)