CVE-2021-20086: Odoo Apps – Cross-Site Scripting via Prototype Pollution

CVE-2021-20086: Odoo Apps - Cross-Site Scripting via Prototype Pollution-渗透云记 - 专注于网络安全与技术分享
CVE-2021-20086: Odoo Apps – Cross-Site Scripting via Prototype Pollution
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2021-20086: Odoo Apps – Cross-Site Scripting via Prototype Pollution

漏洞描述

jquery-bbq 1.2.1 contains a prototype pollution caused by improperly controlled modification of object prototype attributes, letting malicious users inject properties into Object.prototype, exploit requires malicious user interaction.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享