Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2021-32821
Disclosure Date: January 03, 2023 (last updated February 24, 2025)
MooTools is a collection of JavaScript utilities for JavaScript developers. All known versions include a CSS selector parser that is vulnerable to Regular Expression Denial of Service (ReDoS). An attack requires that an attacker can inject a string into a CSS selector at runtime, which is quite common with e.g. jQuery CSS selectors. No patches are available for this issue.
0
Attacker Value
Unknown
CVE-2021-23432
Disclosure Date: August 24, 2021 (last updated November 28, 2024)
This affects all versions of package mootools. This is due to the ability to pass untrusted input to Object.merge()
0
Attacker Value
Unknown
CVE-2021-20088
Disclosure Date: April 23, 2021 (last updated February 22, 2025)
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in mootools-more 1.6.0 allows a malicious user to inject properties into Object.prototype.
0