ZeroHour

CVE-2019-12592

CVSS 3.0
6.1 medium
EPSS
1%p63
Published
()
Modified
Description

A universal Cross-site scripting (UXSS) vulnerability in the Evernote Web Clipper extension before 7.11.1 for Chrome allows remote attackers to run arbitrary web script or HTML in the context of any loaded 3rd-party IFrame.

Vendors
evernote
Products
web clipper
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news