Description
In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto__` payload.
Remediation
References
Related Vulnerabilities
MySQL Other Vulnerability (CVE-2006-1517)
WordPress Plugin Google Authenticator Unspecified Vulnerability (0.47)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4584)
WordPress Plugin SB Welcome Email Editor Unspecified Vulnerability (4.1)
WordPress Plugin Augmented reality Unspecified Vulnerability (1.2.0)