Impact
An attacker can inject arbitrary script through the addDiv function of the popup.html component, due to the lack of input sanitization. This basic cross‑Site Scripting allows malicious code to execute within the context of the extension’s popup interface and could expose sensitive data or alter the user experience. The vulnerability is classified as a CWE-74 and CWE-80, both of which represent cross‑Site Scripting weaknesses.
Affected Systems
The flaw exists in Alaev:SEO Tools Extension versions up to 1.0.10 on Google Chrome. Users running any of these affected releases should seek a fix.
Risk and Exploitability
The CVSS score of 5.3 denotes a moderate severity, and the EPSS score is not available, indicating no known widespread exploitation yet. The vulnerability is not listed in the CISA KEV catalog. Attackers can initiate the exploit remotely by manipulating the extension’s page SEO fields; the public exploit demonstrates that malicious code can be executed from the popup UI. While the impact is contained to the extension interface, remediation is recommended to mitigate potential data exposure or malicious content injection.
OpenCVE Enrichment