VYPR
Medium severity6.5NVD Advisory· Published Apr 8, 2019· Updated Jun 17, 2026

CVE-2019-10845

CVE-2019-10845

Description

An issue was discovered in Uniqkey Password Manager 1.14. When entering new credentials to a site that isn't registered within this product, a pop-up window will appear asking the user if they want to save these new credentials. The code of the pop-up window can be read and, to some extent, manipulated by remote servers. This pop-up window will stay on any page the user visits within the browser until a decision is made. A malicious web server can forcefully manipulate the pop-up and cause it not to appear, stopping users from securing their credentials. This vulnerability is related to id="uniqkey-password-popup" and password-popup/popup.html, but is a different vulnerability than CVE-2019-10676.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • cpe:2.3:a:uniqkey:password_manager:1.14:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:uniqkey:password_manager:1.14:*:*:*:*:*:*:*
    • (no CPE)range: = 1.14

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.