Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-44683

Опубликовано: 25 мар. 2022
Источник: nvd
CVSS3: 8.2
CVSS2: 5.8
EPSS Низкий

Описание

The DuckDuckGo browser 7.64.4 on iOS allows Address Bar Spoofing due to mishandling of the JavaScript window.open function (used to open a secondary browser window). This could be exploited by tricking users into supplying sensitive information such as credentials, because the address bar would display a legitimate URL, but content would be hosted on the attacker's web site.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:duckduckgo:duckduckgo:*:*:*:*:*:iphone_os:*:*
Версия до 7.64.18 (исключая)

EPSS

Процентиль: 51%
0.00282
Низкий

8.2 High

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-1021

Связанные уязвимости

CVSS3: 8.2
github
почти 4 года назад

The DuckDuckGo browser 7.64.4 on iOS allows Address Bar Spoofing due to mishandling of the JavaScript window.open function (used to open a secondary browser window). This could be exploited by tricking users into supplying sensitive information such as credentials, because the address bar would display a legitimate URL, but content would be hosted on the attacker's web site.

EPSS

Процентиль: 51%
0.00282
Низкий

8.2 High

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-1021