CVE-2019-12592

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
18/06/2019
Last modified:
19/06/2019

Description

A universal Cross-site scripting (UXSS) vulnerability in the Evernote Web Clipper extension before 7.11.1 for Chrome allows remote attackers to run arbitrary web script or HTML in the context of any loaded 3rd-party IFrame.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:evernote:web_clipper:*:*:*:*:*:chrome:*:* 7.11.1 (excluding)