What the vulnerability does
01Description
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Rajesh Thanoch Quick Learn quick-learn allows Object Injection.This issue affects Quick Learn: from n/a through <= 1.0.1.
Explanation of Vulnerability in Simple Terms
02Summary
Quick Learn versions 1.0.1 and earlier contain a critical vulnerability that allows unauthenticated attackers to read sensitive data, modify content, or disrupt service without any user interaction. The vulnerability is accessible over the network with low attack complexity. No authentication or special privileges are required to exploit it.
What an attacker can do
03Attacker Capabilities
Read sensitive data, modify content, or disrupt the service without authentication.
Potential impact on your site
04Site Impact
Any site running Quick Learn ≤1.0.1 is immediately compromised; attackers can access all data and modify or delete content.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
November 20, 2024
CVE published
April 28, 2026
Record updated