Description
The package mathjs before 7.5.1 are vulnerable to Prototype Pollution via the deepExtend function that runs upon configuration updates.
Remediation
References
Related Vulnerabilities
WordPress Plugin GTM4WP Cross-Site Scripting (1.15)
WordPress Plugin Social Articles Security Bypass (2.4)
WordPress Plugin WordPress Backup and Migrate-Backup Guard Arbitrary File Upload (1.5.9)
MySQL CVE-2019-2693 Vulnerability (CVE-2019-2693)
WordPress Plugin Drag and Drop Multiple File Upload-Contact Form 7 Cross-Site Scripting (1.3.6.2)