Vulnerabilities > CVE-2019-10781 - Exposure of Resource to Wrong Sphere vulnerability in Schema-Inspector Project Schema-Inspector

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
schema-inspector-project
CWE-668
critical

Summary

In schema-inspector before 1.6.9, a maliciously crafted JavaScript object can bypass the `sanitize()` and the `validate()` function used within schema-inspector.

Common Weakness Enumeration (CWE)