CVE-2020-7746


Prototype Pollution

This affects the package chart.js before 2.9.4. The options parameter is not properly sanitized when it is processed. When the options are processed, the existing options (or the defaults options) are deeply merged with provided options. However, during this operation, the keys of the object being set are not checked, leading to a prototype pollution.



We have discovered 69,725 live websites that are affected by CVE-2020-7746.

Contact us to get more info




Affected Software

Product  Chart.js
Category Charting
Vulnerable Versions
  • from 0 before 2.9.4
Total Vulnerable Versions101
Vulnerable Domains69,725 live websites (90.60% of Chart.js install base)


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2020-7746 and the relative popularity of websites


Details

  • Published - Oct 29, 2020
  • Updated - Oct 29, 2020

Credits

  • Alessio Della Libera (d3lla)




Countries

United States19,304 websites



Germany6,240 websites
Italy4,155 websites
France3,987 websites
GB3,814 websites
Spain2,749 websites
Netherlands2,446 websites
Brazil2,119 websites
Canada1,745 websites
Australia1,475 websites

TLDs

.com28,441 websites
.de4,035 websites
.org3,736 websites
.it2,705 websites
.co.uk2,099 websites
.nl1,979 websites
.net1,634 websites
.fr1,611 websites
.com.br1,610 websites
.com.au1,132 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2020-7746 through included software libraries and plugins.



References


Websites affected by CVE-2020-7746

Top websites that are affected by CVE-2020-7746. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.***********.jp Japan*,***
*****.com Canada*,***
***.********.****.fr France*,***
****.*******.**********.it Italy**,***
************.com United States**,***
*******.com United States**,***
***.***************.com United States**,***
***.********.de Germany**,***
***.*************.com United States**,***
***.*******.**.uk GB**,***
See full domain list