Lucene search

K
osvGoogleOSV:CVE-2020-26239
HistoryNov 23, 2020 - 7:15 p.m.

CVE-2020-26239

2020-11-2319:15:11
Google
osv.dev
3
scratch addons
webextension
chrome
firefox
dom-based xss
more links
html-escaped
unescaped
xss
automatic update
browser
disabled

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

31.7%

Scratch Addons is a WebExtension that supports both Chrome and Firefox. Scratch Addons before version 1.3.2 is vulnerable to DOM-based XSS. If the victim visited a specific website, the More Links addon of the Scratch Addons extension used incorrect regular expression which caused the HTML-escaped values to be unescaped, leading to XSS. Scratch Addons version 1.3.2 fixes the bug. The extension will be automatically updated by the browser. More Links addon can be disabled via the option of the extension.

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

31.7%

Related for OSV:CVE-2020-26239