jorgerdemocorp-mend-selfhosted / test-to-delete

0 stars 0 forks source link

wpmenumaker1.1.2: 1 vulnerabilities (highest severity is: 8.8) #5

Closed mend-app-sh[bot] closed 7 months ago

mend-app-sh[bot] commented 7 months ago
Vulnerable Library - wpmenumaker1.1.2

Library home page: https://plugins.svn.wordpress.org/wpmenumaker

Found in HEAD commit: 58e1a6a752131b5722c0e86dc7c0e6db8ecdaf10

Vulnerable Source Files (1)

/jquery.ba-bbq.js

Vulnerabilities

CVE Severity CVSS Dependency Type Fixed in (wpmenumaker1.1.2 version) Remediation Possible**
CVE-2021-20086 High 8.8 wpmenumaker1.1.2 Direct N/A

**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation

Details

CVE-2021-20086 ### Vulnerable Library - wpmenumaker1.1.2

Library home page: https://plugins.svn.wordpress.org/wpmenumaker

Found in HEAD commit: 58e1a6a752131b5722c0e86dc7c0e6db8ecdaf10

Found in base branch: main

### Vulnerable Source Files (1)

/jquery.ba-bbq.js

### Vulnerability Details

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-bbq 1.2.1 allows a malicious user to inject properties into Object.prototype.

Publish Date: 2021-04-23

URL: CVE-2021-20086

### CVSS 3 Score Details (8.8)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: Low - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: High - Integrity Impact: High - Availability Impact: High

For more information on CVSS3 Scores, click here.