9.8
CVE-2021-23432
- EPSS 0.89%
- Veröffentlicht 24.08.2021 09:15:08
- Zuletzt bearbeitet 21.11.2024 05:51:44
- Quelle report@snyk.io
- CVE-Watchlists
- Unerledigt
Prototype Pollution
This affects all versions of package mootools. This is due to the ability to pass untrusted input to Object.merge()
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mootools Project ≫ Mootools SwPlatformnode.js
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.89% | 0.546 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
| report@snyk.io | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
|
https://snyk.io/vuln/SNYK-JS-MOOTOOLS-1325536