OroPlatform is a PHP Business Application Platform. In affected versions by sending a specially crafted request, an attacker could inject properties into existing JavaScript language construct prototypes, such as objects. Later this injection may lead to JS code execution by libraries that are vulnerable to Prototype Pollution. This issue has been patched in version 4.2.8. Users unable to upgrade may configure a firewall to drop requests containing next strings: `__proto__` , `constructor[prototype]`, and `constructor.prototype` to mitigate this issue.
History

Wed, 23 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2022-01-04T19:40:10.000Z

Updated: 2025-04-23T19:15:19.979Z

Reserved: 2021-11-16T00:00:00.000Z

Link: CVE-2021-43852

cve-icon Vulnrichment

Updated: 2024-08-04T04:10:16.362Z

cve-icon NVD

Status : Modified

Published: 2022-01-04T20:15:07.730

Modified: 2024-11-21T06:29:55.940

Link: CVE-2021-43852

cve-icon Redhat

No data.