Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qvxp-wqpj-8gwf

Опубликовано: 12 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.3

Описание

Improper access control vulnerability in McAfee WebAdvisor Chrome and Edge browser extensions up to 8.1.0.1895 allows a remote attacker to gain access to McAfee WebAdvisor settings and other details about the user’s system. This could lead to unexpected behaviors including; settings being changed, fingerprinting of the system leading to targeted scams, and not triggering the malicious software if McAfee software is detected.

Improper access control vulnerability in McAfee WebAdvisor Chrome and Edge browser extensions up to 8.1.0.1895 allows a remote attacker to gain access to McAfee WebAdvisor settings and other details about the user’s system. This could lead to unexpected behaviors including; settings being changed, fingerprinting of the system leading to targeted scams, and not triggering the malicious software if McAfee software is detected.

EPSS

Процентиль: 59%
0.00381
Низкий

7.3 High

CVSS3

Дефекты

CWE-284
CWE-668

Связанные уязвимости

CVSS3: 6.5
nvd
почти 4 года назад

Improper access control vulnerability in McAfee WebAdvisor Chrome and Edge browser extensions up to 8.1.0.1895 allows a remote attacker to gain access to McAfee WebAdvisor settings and other details about the user’s system. This could lead to unexpected behaviors including; settings being changed, fingerprinting of the system leading to targeted scams, and not triggering the malicious software if McAfee software is detected.

CVSS3: 7.3
fstec
почти 4 года назад

Уязвимость плагина антивирусной защиты McAfee WebAdvisor для браузеров Chrome и Edge, связанная с недостатками контроля доступа, позволяющая нарушителю получить доступ к настройкам плагина и другим сведениям о системе пользователя

EPSS

Процентиль: 59%
0.00381
Низкий

7.3 High

CVSS3

Дефекты

CWE-284
CWE-668