CVE-2019-10805

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/02/2020
Last modified:
05/03/2020

Description

valib through 2.0.0 allows Internal Property Tampering. A maliciously crafted JavaScript object can bypass several inspection functions provided by valib. Valib uses a built-in function (hasOwnProperty) from the unsafe user-input to examine an object. It is possible for a crafted payload to overwrite this function to manipulate the inspection results to bypass security checks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sideralis:valib.js:*:*:*:*:*:node.js:*:* 2.0.0 (including)