Lucene search

K
cveMitreCVE-2019-18893
HistoryJan 13, 2020 - 5:15 p.m.

CVE-2019-18893

2020-01-1317:15:11
CWE-79
mitre
web.nvd.nist.gov
72
cve-2019-18893
xss
video downloader
avast secure browser
avg secure browser
security vulnerability
web browser security

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

37.3%

XSS in the Video Downloader component before 1.5 of Avast Secure Browser 77.1.1831.91 and AVG Secure Browser 77.0.1790.77 allows websites to execute their code in the context of this component. While Video Downloader is technically a browser extension, it is granted a very wide set of privileges and can for example access cookies and browsing history, spy on the user while they are surfing the web, and alter their surfing experience in almost arbitrary ways.

Affected configurations

Nvd
Node
avastsecure_browserMatch77.1.1831.91
OR
avgsecure_browserMatch77.0.1790.77
OR
video_downloader_projectvideo_downloaderRange<1.5
VendorProductVersionCPE
avastsecure_browser77.1.1831.91cpe:2.3:a:avast:secure_browser:77.1.1831.91:*:*:*:*:*:*:*
avgsecure_browser77.0.1790.77cpe:2.3:a:avg:secure_browser:77.0.1790.77:*:*:*:*:*:*:*
video_downloader_projectvideo_downloader*cpe:2.3:a:video_downloader_project:video_downloader:*:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

37.3%

Related for CVE-2019-18893