Vulnerabilities > Fehelper Project

DATE CVE VULNERABILITY TITLE RISK
2019-06-26 CVE-2019-12966 Injection vulnerability in Fehelper Project Fehelper 20190619
FeHelper through 2019-06-19 allows arbitrary code execution during a JSON format operation, as demonstrated by the {"a":(function(){confirm(1)})()} input.
network
low complexity
fehelper-project CWE-74
critical
9.8