Armor-test / broken_crystals_scan

A vulnerable Application in crystal
0 stars 1 forks source link

xmlhttprequest-ssl : = 1.5.5 - xmlhttprequest and xmlhttprequest-ssl vulnerable to Arbitrary Code Injection #12

Open armorcodegithubpreprod[bot] opened 4 months ago

armorcodegithubpreprod[bot] commented 4 months ago

This affects the package xmlhttprequest before 1.7.0; all versions of package xmlhttprequest-ssl. Provided requests are sent synchronously (async=False on xhr.open), malicious user input flowing into xhr.send could result in arbitrary code being injected and run.

References:

File Path: yarn.lock

Mitigation: Patched version: 1.6.2

Tool Finding Id: RVA_kwDOKhg_f88AAAABM_wEQg

armorcodegithubpreprod[bot] commented 4 months ago

Finding [55222328] status changed to Confirmed Note:
by pragati.dubey@armorcode.io via ArmorCode Platform