FeHelper through 2019-06-19 allows arbitrary code execution during a JSON format operation, as demonstrated by the {"a":(function(){confirm(1)})()} input.
References
Link | Resource |
---|---|
https://github.com/zxlie/FeHelper/issues/63 | Exploit Issue Tracking Third Party Advisory |
Configurations
History
No history.
Information
Published : 2019-06-26 12:15
Updated : 2024-02-28 17:08
NVD link : CVE-2019-12966
Mitre link : CVE-2019-12966
CVE.ORG link : CVE-2019-12966
JSON object : View
Products Affected
fehelper_project
- fehelper
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')