Unrated severityNVD Advisory· Published Apr 29, 2019· Updated Aug 4, 2024
CVE-2019-11594
CVE-2019-11594
Description
In AdBlock before 3.45.0, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a client-side session when a web service loads a script for execution using XMLHttpRequest or Fetch, and the script origin has an open redirect.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- armin.dev/blog/2019/04/adblock-plus-code-injection/mitrex_refsource_MISC
- blog.getadblock.com/adblock-for-chrome-3-45-0-resolving-a-potential-security-risk-b21647a26df6mitrex_refsource_MISC
- news.ycombinator.com/itemmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.