Prototype Pollution in vConsole v3.15.0 by Tencent
CVE-2023-30363
9.8CRITICAL
What is CVE-2023-30363?
vConsole v3.15.0 has been found to contain a prototype pollution vulnerability arising from improper handling of key and value resolution in the setOptions function within core.ts. This could potentially allow an attacker to manipulate the object's prototype, leading to unexpected behavior or security risks in applications using this version of vConsole.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved