Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j72f-vfwh-m8f9

Опубликовано: 18 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

The devtools API in Whale browser before 3.12.129.18 allowed extension developers to inject arbitrary JavaScript into the extension store web page via devtools.inspectedWindow, leading to extensions downloading and uploading when users open the developer tool.

The devtools API in Whale browser before 3.12.129.18 allowed extension developers to inject arbitrary JavaScript into the extension store web page via devtools.inspectedWindow, leading to extensions downloading and uploading when users open the developer tool.

EPSS

Процентиль: 42%
0.00197
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
почти 4 года назад

The devtools API in Whale browser before 3.12.129.18 allowed extension developers to inject arbitrary JavaScript into the extension store web page via devtools.inspectedWindow, leading to extensions downloading and uploading when users open the developer tool.

EPSS

Процентиль: 42%
0.00197
Низкий

6.1 Medium

CVSS3