CVE-2023-5718

CVSS V2 None CVSS V3 None
Description
The Vue.js Devtools extension was found to leak screenshot data back to a malicious web page via the standard `postMessage()` API. By creating a malicious web page with an iFrame targeting a sensitive resource (i.e. a locally accessible file or sensitive website), and registering a listener on the web page, the extension sent messages back to the listener, containing the base64 encoded screenshot data of the sensitive resource.
Overview
  • CVE ID
  • CVE-2023-5718
  • Assigner
  • snyk
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-10-23T14:02:43.544Z
  • Last Modified Date
  • 2023-10-23T14:04:21.011Z
History
Created Old Value New Value Data Type Notes
2024-06-25 05:06:43 Added to TrackCVE