在 Chrome 浏览器上的 vidIQ Vision for YouTube 扩展程序 3.199.0 版本中发现了一个安全漏洞。受影响的组件是 postMessage Handler 中的 函数。通过对参数 进行操纵,可导致信息泄露。该漏洞可被远程利用,且利用方式已公开,可能被用于发起攻击。厂商说明:“目前,vidIQ 不接收安全漏洞提交,也没有建立漏洞赏金计划。”
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| vidIQ | Vision for YouTube Extension | 3.199.0 |
cpe:2.3:a:vidiq:vision_for_youtube_extension:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet