WebFeed is a lightweight web feed reader extension for Firefox/Chrome. Multiple HTML injection vulnerabilities in WebFeed can lead to CSRF and UI spoofing attacks. A remote attacker can provide malicious RSS feeds and attract the victim user to visit it using WebFeed. The attacker can then inject malicious HTML into the extension page and fool the victim into sending out HTTP requests to arbitrary sites with the victim's credentials. Users are vulnerable to CSRF attacks when visiting malicious RSS feeds via WebFeed. Unwanted actions could be executed on the user's behalf on arbitrary websites. This issue has been addressed in release version 0.9.2. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Metrics
Affected Vendors & Products
References
History
Tue, 05 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Taoso
Taoso webfeed |
|
CPEs | cpe:2.3:a:taoso:webfeed:*:*:*:*:*:*:*:* | |
Vendors & Products |
Taoso
Taoso webfeed |
|
Metrics |
ssvc
|
Mon, 04 Nov 2024 23:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | WebFeed is a lightweight web feed reader extension for Firefox/Chrome. Multiple HTML injection vulnerabilities in WebFeed can lead to CSRF and UI spoofing attacks. A remote attacker can provide malicious RSS feeds and attract the victim user to visit it using WebFeed. The attacker can then inject malicious HTML into the extension page and fool the victim into sending out HTTP requests to arbitrary sites with the victim's credentials. Users are vulnerable to CSRF attacks when visiting malicious RSS feeds via WebFeed. Unwanted actions could be executed on the user's behalf on arbitrary websites. This issue has been addressed in release version 0.9.2. All users are advised to upgrade. There are no known workarounds for this vulnerability. | |
Title | WebFeed HTML injection vulnerabilities | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-11-04T23:13:13.768Z
Updated: 2024-11-05T16:43:45.147Z
Reserved: 2024-10-22T17:54:40.956Z
Link: CVE-2024-50346
Vulnrichment
Updated: 2024-11-05T16:43:24.361Z
NVD
Status : Awaiting Analysis
Published: 2024-11-05T00:15:04.510
Modified: 2024-11-05T16:04:26.053
Link: CVE-2024-50346
Redhat
No data.