Unrated severityNVD Advisory· Published Dec 27, 2018· Updated Sep 17, 2024
CVE-2018-20524
CVE-2018-20524
Description
The Chat Anywhere extension 2.4.0 for Chrome allows XSS via crafted use of < in a message, because a danmuWrapper DIV element in chatbox-only\danmu.js is outside the scope of a Content Security Policy (CSP).
Affected products
2- Range: = 2.4.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- vul.su.ki/posts/Chat_Anywhere_2.4.0_XSS.md/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.