Description
The package mathjs before 7.5.1 are vulnerable to Prototype Pollution via the deepExtend function that runs upon configuration updates.
Remediation
References
Related Vulnerabilities
WordPress Plugin BulletProof Security Multiple Cross-Site Scripting Vulnerabilities (.48.9)
Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-20411)
Squid Improper Input Validation Vulnerability (CVE-2016-2570)
WordPress 5.7 Multiple Vulnerabilities (5.7)
WordPress Plugin Error Log Viewer by BestWebSoft Cross-Site Scripting (1.0.5)