Description
Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.
Remediation
References
Related Vulnerabilities
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-2987)
Oracle Database Server CVE-2005-4884 Vulnerability (CVE-2005-4884)
MySQL CVE-2019-2486 Vulnerability (CVE-2019-2486)
WordPress Plugin Salon Booking System Arbitrary File Upload (10.2)
WordPress Plugin Connections Business Directory CSV Injection (9.6)