CVE-2024-29384

An issue in CSS Exfil Protection v.1.1.0 allows a remote attacker to obtain sensitive information via the content.js and parseCSSRules functions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mikegualtieri:css_exfil_protection:1.1.0:*:*:*:*:*:*:*

History

18 Jun 2025, 18:08

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:mikegualtieri:css_exfil_protection:1.1.0:*:*:*:*:*:*:*
First Time Mikegualtieri
Mikegualtieri css Exfil Protection
References () https://github.com/mlgualtieri/CSS-Exfil-Protection/issues/41 - () https://github.com/mlgualtieri/CSS-Exfil-Protection/issues/41 - Exploit, Issue Tracking, Vendor Advisory
References () https://github.com/randshell/vulnerability-research/tree/main/CVE-2024-29384 - () https://github.com/randshell/vulnerability-research/tree/main/CVE-2024-29384 - Exploit, Third Party Advisory

21 Nov 2024, 09:07

Type Values Removed Values Added
References () https://github.com/mlgualtieri/CSS-Exfil-Protection/issues/41 - () https://github.com/mlgualtieri/CSS-Exfil-Protection/issues/41 -
References () https://github.com/randshell/vulnerability-research/tree/main/CVE-2024-29384 - () https://github.com/randshell/vulnerability-research/tree/main/CVE-2024-29384 -

03 Jul 2024, 01:52

Type Values Removed Values Added
Summary
  • (es) Un problema en CSS Exfil Protection v.1.1.0 permite a un atacante remoto obtener información confidencial a través de las funciones content.js y parseCSSRules.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-200

30 Apr 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-30 20:15

Updated : 2025-06-18 18:08


NVD link : CVE-2024-29384

Mitre link : CVE-2024-29384

CVE.ORG link : CVE-2024-29384


JSON object : View

Products Affected

mikegualtieri

  • css_exfil_protection
CWE
NVD-CWE-noinfo CWE-200

Exposure of Sensitive Information to an Unauthorized Actor