All versions of package querymen are vulnerable to Prototype Pollution if the parameters of exported function handler(type, name, fn) can be controlled by users without any sanitization. Note: This vulnerability derives from an incomplete fix of [CVE-2020-7600](https://security.snyk.io/vuln/SNYK-JS-QUERYMEN-559867).
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: snyk

Published: 2022-06-17T20:05:34.384841Z

Updated: 2024-09-17T00:05:54.947Z

Reserved: 2022-02-24T00:00:00

Link: CVE-2022-25871

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-06-17T20:15:10.670

Modified: 2022-06-28T15:27:14.130

Link: CVE-2022-25871

cve-icon Redhat

No data.