parseQuery of the file parseQuery.js. Performing a manipulation of the argument Name results in improperly controlled modification of object prototype attributes.
This vulnerability was named CVE-2022-37601. The attack needs to be approached within the local network. There is no available exploit.
Intelligence View
⚡ tsecurity.de Intelligence
CVE-2022-37601 | webpack loader-utils 2.0.0 parseQuery.js parseQuery Name prototype pollution (Issue 212 / WID-SEC-2026-2460)
Reagiere als Erste:r — dein Feedback zählt!
A vulnerability marked as problematic has been reported in webpack loader-utils 2.0.0. This issue affects the function
SOCIAL SHARE CARD GENERATOR