Description
math.js before 3.17.0 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name could result arbitrary execution.
Remediation
References
Related Vulnerabilities
WordPress Plugin IWantOneButton 'updateAJAX.php' SQL Injection (3.0.1)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-2787)
WordPress Plugin 3DPrint Lite Arbitrary File Upload (1.9.1.4)
XWiki Improper Neutralization of Alternate XSS Syntax Vulnerability (CVE-2023-35158)
WordPress Plugin FormGet Contact Form Cross-Site Scripting (5.3)