CVE-2020-28448

Published
View on NVD ↗
CVSS v3
5.6
MEDIUM
CVSS v2
7.5
HIGH
Affected
1
PROJECT

Description

This affects the package multi-ini before 2.1.1. It is possible to pollute an object's prototype by specifying the proto object as part of an array.

Read multilevel and multiline ini files in compatible with Zend.
GitHubGitHub
11