#VU23454 Input validation error in jpv - CVE-2019-19507
Published: December 9, 2019
jpv
Manvel Khnkoyan
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can use a specially crafted json, bypass "compareCommon()", and manipulate the type detection result, because certain internal attributes can be overwritten via a conflicting name, as demonstrated by 'constructor': {'name':'Array'}.