DOJO CHALLENGE #13 Winners!
ID: 622b371d-d42a-50ba-b5a4-1e17eaf05b9c
STIX ID: report--622b371d-d42a-50ba-b5a4-1e17eaf05b9c
Feed Name: YesWeHack Blog
Threat Score
This DOJO Challenge #13 write-up explains how an attacker can use prototype pollution (via constructor.prototype as an alternative to __proto__) to place a code property on an object's prototype so that a blacklist-based deletion of options.code fails, allowing execution of arbitrary JavaScript through new Function; the report includes source code, step-by-step analysis, a PoC JSON payload, and references.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
