Skip to content

DOM-based Cross-Site Scripting

High
apple502j published GHSA-6qfq-px3r-xj4p Nov 23, 2020

Package

No package listed

Affected versions

<1.3.2

Patched versions

1.3.2

Description

Scratch Addons browser extension for Chrome and Firefox before version 1.3.2 is vulnerable to DOM-based XSS.

Impact

If the victim visited a specific website, the More Links addon of the Scratch Addons extension used incorrect regular expression which caused the HTML-escaped values to be unescaped, leading to XSS.

CVSS v3.1 Score: 7.6(High) - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:N

Patches

Scratch Addons version 1.3.2 fixes the bug. The extension will be automatically updated by the browser.

Workarounds

More Links addon can be disabled via the option of the extension.

References

Severity

High

CVE ID

CVE-2020-26239

Weaknesses

No CWEs

Credits