The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Link | Tags |
---|---|
https://snyk.io/vuln/SNYK-JS-TOTAL4-1130527 | exploit third party advisory patch |
https://github.com/totaljs/framework4/blob/master/utils.js%23L5430-L5455 | broken link |
https://github.com/totaljs/framework4/commit/8a72d8c20f38bbcac031a76a51238aa528f68821 | third party advisory patch |