CVE-2022-2564
Vulnerability Description
Prototype Pollution in GitHub repository automattic/mongoose prior to 6.4.6.
Prototype Pollution in GitHub repository automattic/mongoose prior to 6.4.6.
admin/partials/wp-splashing-admin-main.php in the Splashing Images plugin (wp-splashing-images) before 2.1.1 for WordPress allows authenticated (administrator, editor, or author) remote attackers to c...
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Administration module by an Admin user.
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the UpgradeWizard module by an Admin user.
An issue was discovered in CMS Made Simple 2.2.8. In the administrator page admin/changegroupperm.php, it is possible to send a crafted value in the sel_groups parameter that leads to authenticated ob...
This affects the package json-pointer before 0.6.1. Multiple reference of object using slash is supported.
pathval before version 1.1.1 is vulnerable to prototype pollution.