CVE-2024-49378

smartUp, a web browser mouse gestures extension, has a universal cross-site scripting issue in the Edge and Firefox versions of smartUp 7.2.622.1170. The vulnerability allows another extension to execute arbitrary code in the context of the user’s tab. As of time of publication, no known patches exist.
Configurations

No configuration.

History

28 Oct 2024, 13:58

Type Values Removed Values Added
Summary
  • (es) smartUp, una extensión de gestos del ratón para navegadores web, presenta un problema de Cross Site Scripting universal en las versiones Edge y Firefox de smartUp 7.2.622.1170. La vulnerabilidad permite que otra extensión ejecute código arbitrario en el contexto de la pestaña del usuario. Al momento de la publicación, no existían parches conocidos.

25 Oct 2024, 15:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

25 Oct 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-25 13:15

Updated : 2024-10-28 13:58


NVD link : CVE-2024-49378

Mitre link : CVE-2024-49378

CVE.ORG link : CVE-2024-49378


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')