Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36683
HistoryAug 11, 2022 - 11:47 a.m.

Injection Vulnerability

2022-08-1111:47:23
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
chrome
injection
vulnerability
untrusted input
validation
settings
attacker
malicious extension
scripts
html
privileged page

EPSS

0.001

Percentile

44.1%

chrome has injection vulnerability. The vulnerability exists due to a lack of validation of untrusted input in Settings allowing an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted HTML page.