math.js prior to 3.17.0 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name could result arbitrary execution.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
mathjs math.js |