Vulnerabilities > CVE-2023-26102 - Unspecified vulnerability in Rangy Project Rangy
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
LOW Availability impact
HIGH Summary
All versions of the package rangy are vulnerable to Prototype Pollution when using the extend() function in file rangy-core.js.The function uses recursive merge which can lead an attacker to modify properties of the Object.prototype
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |