Description
Versions of package locutus before 2.0.12 are vulnerable to prototype Pollution via the php.strings.parse_str function.
Remediation
References
https://github.com/kvz/locutus/pull/418/
https://snyk.io/vuln/SNYK-JS-LOCUTUS-598675
Related Vulnerabilities
CVE-2022-24723 Vulnerability in npm package urijs
CVE-2022-25647 Vulnerability in maven package com.google.code.gson:gson
CVE-2022-31166 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2023-26474 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2023-29566 Vulnerability in npm package dawnsparks-node-tesseract