CVE-2024-33436

An issue in CSS Exfil Protection v.1.1.0 allows a remote attacker to obtain sensitive information due to missing support for CSS variables
Configurations

Configuration 1 (hide)

cpe:2.3:a:mikegualtieri:css_exfil_protection:1.1.0:*:*:*:*:*:*:*

History

18 Jun 2025, 18:07

Type Values Removed Values Added
References () https://github.com/mlgualtieri/CSS-Exfil-Protection/issues/41 - () https://github.com/mlgualtieri/CSS-Exfil-Protection/issues/41 - Exploit, Issue Tracking, Vendor Advisory
References () https://github.com/randshell/vulnerability-research/tree/main/CVE-2024-33436 - () https://github.com/randshell/vulnerability-research/tree/main/CVE-2024-33436 - Exploit, Third Party Advisory
CPE cpe:2.3:a:mikegualtieri:css_exfil_protection:1.1.0:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
First Time Mikegualtieri
Mikegualtieri css Exfil Protection

14 Mar 2025, 18:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CWE CWE-200

21 Nov 2024, 09:16

Type Values Removed Values Added
References () https://github.com/mlgualtieri/CSS-Exfil-Protection/issues/41 - () https://github.com/mlgualtieri/CSS-Exfil-Protection/issues/41 -
References () https://github.com/randshell/vulnerability-research/tree/main/CVE-2024-33436 - () https://github.com/randshell/vulnerability-research/tree/main/CVE-2024-33436 -
Summary
  • (es) Un problema en CSS Exfil Protection v.1.1.0 permite a un atacante remoto obtener información confidencial debido a la falta de soporte para variables CSS

30 Apr 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-30 20:15

Updated : 2025-06-18 18:07


NVD link : CVE-2024-33436

Mitre link : CVE-2024-33436

CVE.ORG link : CVE-2024-33436


JSON object : View

Products Affected

mikegualtieri

  • css_exfil_protection
CWE
NVD-CWE-noinfo CWE-200

Exposure of Sensitive Information to an Unauthorized Actor