Showing 1 vulnerability on this page for React Developer Tools Extension

Signals CISA KEV Ransomware Nuclei
Meta vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

React Developer Tools extension Improper Authorization vulnerability

The React Developer Tools extension registers a message listener with window.addEventListener('message', <listener>) in a content script that is accessible to any webpage that is active in the browser. Within the listener is code that requests a URL derived from the received message via fetch(). The URL is not validated or sanitised before it is fetched, thus allowing a malicious web page to arbitrarily fetch URL’s via the victim's browser.

CWE-116CWE-285Oct 19, 2023
CVSS-v4.0EPSS0.467%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX