Vulnerabilities > CVE-2020-7616 - Unspecified vulnerability in Express-Mock-Middleware Project Express-Mock-Middleware 0.0.6
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
LOW Availability impact
NONE Summary
express-mock-middleware through 0.0.6 is vulnerable to Prototype Pollution. Exported functions by the package can be tricked into adding or modifying properties of the `Object.prototype`. Exploitation of this vulnerability requires creation of a new directory where an attack code can be placed which will then be exported by `express-mock-middleware`. As such, this is considered to be a low risk.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |