A vulnerability was determined in jQWidgets up to 24.0.1. This affects the function JQXLite.extend/jqxBaseFramework.extend of the file jqwidgets/jqx-all.js. This manipulation causes improperly controlled modification of object prototype attributes.
The attack can be initiated remotely. The reported GitHub issue was closed with the label "not planned".
Attack Parameters
Impact Assessment
CVSS Vector v4.0