Vulnerabilities > CVE-2020-7616 - Unspecified vulnerability in Express-Mock-Middleware Project Express-Mock-Middleware 0.0.6

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
NONE
network
low complexity
express-mock-middleware-project

Summary

express-mock-middleware through 0.0.6 is vulnerable to Prototype Pollution. Exported functions by the package can be tricked into adding or modifying properties of the `Object.prototype`. Exploitation of this vulnerability requires creation of a new directory where an attack code can be placed which will then be exported by `express-mock-middleware`. As such, this is considered to be a low risk.

Vulnerable Configurations

Part Description Count
Application
Express-Mock-Middleware_Project
1