← Back to CVE List

CVE-2019-10805

Published: 2020-02-28T21:15Z
Last Modified: 2024-11-21T04:19Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
valib through 2.0.0 allows Internal Property Tampering. A maliciously crafted JavaScript object can bypass several inspection functions provided by valib. Valib uses a built-in function (hasOwnProperty) from the unsafe user-input to examine an object. It is possible for a crafted payload to overwrite this function to manipulate the inspection results to bypass security checks. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt