Description
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in backbone-query-parameters 0.4.0 allows a malicious user to inject properties into Object.prototype.
Remediation
References
https://github.com/BlackFan/client-side-prototype-pollution/blob/master/pp/backbone-qp.md
Related Vulnerabilities
CVE-2022-2900 Vulnerability in npm package parse-url
CVE-2023-36542 Vulnerability in maven package org.apache.nifi:nifi-standard-processors
CVE-2023-24998 Vulnerability in maven package org.apache.tomcat:tomcat-util
CVE-2023-5573 Vulnerability in npm package @vrite/sdk
CVE-2023-39022 Vulnerability in maven package opensymphony:oscore