Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-24762

Опубликовано: 14 мар. 2022
Источник: nvd
CVSS3: 6.5
CVSS2: 4.3
EPSS Низкий

Описание

sysend.js is a library that allows a user to send messages between pages that are open in the same browser. Users that use cross-origin communication may have their communications intercepted. Impact is limited by the communication occurring in the same browser. This issue has been patched in sysend.js version 1.10.0. The only currently known workaround is to avoid sending communications that a user does not want to have intercepted via sysend messages.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:sysend.js_project:sysend.js:*:*:*:*:*:node.js:*:*
Версия до 1.10.0 (исключая)

EPSS

Процентиль: 42%
0.00197
Низкий

6.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-200
CWE-346

Связанные уязвимости

CVSS3: 6.5
github
почти 4 года назад

Leaking of user information on Cross-Domain communication in sysend

EPSS

Процентиль: 42%
0.00197
Низкий

6.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-200
CWE-346