Vulnerabilities > CVE-2021-44908 - Unspecified vulnerability in Sailsjs Sails
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
SailsJS Sails.js <=1.4.0 is vulnerable to Prototype Pollution via controller/load-action-modules.js, function loadActionModules().
Vulnerable Configurations
References
- https://github.com/balderdashy/sails/blob/master/lib/app/private/controller/load-action-modules.js#L32
- https://github.com/balderdashy/sails/blob/master/lib/app/private/controller/load-action-modules.js#L32
- https://github.com/balderdashy/sails/issues/7209
- https://github.com/balderdashy/sails/issues/7209
- https://github.com/Marynk/JavaScript-vulnerability-detection/blob/main/sailsJS%20PoC.zip
- https://github.com/Marynk/JavaScript-vulnerability-detection/blob/main/sailsJS%20PoC.zip