billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://cve.naver.com/detail/cve-2025-49223.html |
![]() ![]() |
History
Fri, 06 Jun 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Naver
Naver billboard.js |
|
CPEs | cpe:2.3:a:naver:billboard.js:*:*:*:*:*:*:*:* | |
Vendors & Products |
Naver
Naver billboard.js |
Wed, 04 Jun 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Wed, 04 Jun 2025 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties. | |
Weaknesses | CWE-1321 | |
References |
|

Status: PUBLISHED
Assigner: naver
Published: 2025-06-04T02:00:15.719Z
Updated: 2025-06-04T13:33:44.239Z
Reserved: 2025-06-04T01:29:40.014Z
Link: CVE-2025-49223

No data.

Status : Analyzed
Published: 2025-06-04T03:15:27.190
Modified: 2025-06-06T19:30:16.060
Link: CVE-2025-49223

No data.