Логотип exploitDog
bind:CVE-2018-20524
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-20524

Количество 2

Количество 2

nvd логотип

CVE-2018-20524

около 7 лет назад

The Chat Anywhere extension 2.4.0 for Chrome allows XSS via crafted use of <<a> in a message, because a danmuWrapper DIV element in chatbox-only\danmu.js is outside the scope of a Content Security Policy (CSP).

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-wqqx-5mmq-6phc

больше 3 лет назад

The Chat Anywhere extension 2.4.0 for Chrome allows XSS via crafted use of <<a> in a message, because a danmuWrapper DIV element in chatbox-only\danmu.js is outside the scope of a Content Security Policy (CSP).

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-20524

The Chat Anywhere extension 2.4.0 for Chrome allows XSS via crafted use of <<a> in a message, because a danmuWrapper DIV element in chatbox-only\danmu.js is outside the scope of a Content Security Policy (CSP).

CVSS3: 6.1
0%
Низкий
около 7 лет назад
github логотип
GHSA-wqqx-5mmq-6phc

The Chat Anywhere extension 2.4.0 for Chrome allows XSS via crafted use of <<a> in a message, because a danmuWrapper DIV element in chatbox-only\danmu.js is outside the scope of a Content Security Policy (CSP).

CVSS3: 6.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу