Vulnerabilities/

Code Injection in mquery

Severity:
Medium

Description

lib/utils.js in mquery before 3.2.3 allows a pollution attack because a special property (e.g., proto) can be copied during a merge or clone operation.

Recommendation

Update the mquery package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
mquery
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing