Security Advisory

CVE-2018-20524

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2018-12-27 17:00:00
Last updated 2024-09-17 03:18:30
Assigner mitre
State PUBLISHED

Description

The Chat Anywhere extension 2.4.0 for Chrome allows XSS via crafted use of <<a> in a message, because a danmuWrapper DIV element in chatbox-onlydanmu.js is outside the scope of a Content Security Policy (CSP).