Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Server-Side Request Forgery (SSRF) in MouseTooltipTranslator
Vulnerability Description
The MouseTooltipTranslator Chrome extension allows mouseover translation of any language at once. The MouseTooltipTranslator browser extension is vulnerable to SSRF attacks. The pdf.mjs script uses the URL parameter from the current URL as the file to download and display to the extension user. Because pdf.mjs is imported in viewer.html and viewer.html is accessible to all URLs, an attacker can force the user’s browser to make a request to any arbitrary URL. After discussion with maintainer, patching this issue would require disabling a major feature of the extension in exchange for a low severity vulnerability. Decision to not patch issue.
CVSS Information
N/A
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
MouseTooltipTranslator 代码问题漏洞
Vulnerability Description
MouseTooltipTranslator是daniel k个人开发者的一个鼠标悬停立即翻译任何语言 Chrome 扩展程序。 MouseTooltipTranslator存在代码问题漏洞,该漏洞源于pdf.mjs脚本使用URL参数下载和显示文件,可能导致SSRF攻击。
CVSS Information
N/A
Vulnerability Type
N/A