Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5635-9mvj-r6hp

Опубликовано: 03 сент. 2020
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Malicious Package in vue-backbone

Version 0.1.2 of vue-backbone contained malicious code. The code when executed in the browser would enumerate password, cvc and cardnumber fields from forms and send the extracted values to https://js-metrics.com/minjs.php?pl=

Recommendation

Remove the package from your environment and evaluate your application to determine whether or not user data was compromised.

Пакеты

Наименование

vue-backbone

npm
Затронутые версииВерсия исправления

= 0.1.2

0.1.3

9.8 Critical

CVSS3

Дефекты

CWE-506

9.8 Critical

CVSS3

Дефекты

CWE-506