Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4fw7-9pw4-4mvx

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

content/unity-api.js in the unity-firefox-extension extension 2.4.1 for Firefox exposes the toDataURL function in an API call, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted webpage.

content/unity-api.js in the unity-firefox-extension extension 2.4.1 for Firefox exposes the toDataURL function in an API call, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted webpage.

EPSS

Процентиль: 55%
0.00319
Низкий

Связанные уязвимости

ubuntu
около 13 лет назад

content/unity-api.js in the unity-firefox-extension extension 2.4.1 for Firefox exposes the toDataURL function in an API call, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted webpage.

nvd
около 13 лет назад

content/unity-api.js in the unity-firefox-extension extension 2.4.1 for Firefox exposes the toDataURL function in an API call, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted webpage.

EPSS

Процентиль: 55%
0.00319
Низкий