在 Chrome 浏览器中,Inbox Foundry ActiveInbox 扩展(版本 7.10.24 及更早版本)存在一个漏洞。受影响的组件是 Google OAuth 客户端密钥(Google OAuth Client Secret),具体涉及该组件中 文件中的某个未知函数。通过操纵该函数会导致硬编码的凭据暴露。此攻击可远程执行,且利用代码已在公开渠道可用,有可能已被利用。供应商已提前获知此问题。支持团队解释称:“目前,[漏洞赏金]项目暂时搁置,因为我们正在处理大量现有的报告。”
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Inbox Foundry | ActiveInbox Extension | 7.10.0 |
cpe:2.3:a:inbox_foundry:activeinbox_extension:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet