Looking for the vulnerability index of Invicti's legacy products?
math.js Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2017-1001002) - Vulnerability Database

math.js Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2017-1001002)

Description

math.js before 3.17.0 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name could result arbitrary execution.

Related Vulnerabilities