CVE-2024-49378
CVE-2024-49378: Cross-Site Scripting (XSS) Vulnerability in smartUp Browser Extension. This impacts Edge and Firefox versions of smartUp 7.2.622.1170, a popular web browser mouse gestures extension. The vulnerability enables arbitrary code execution by another extension within the user's current tab.
This XSS flaw allows malicious actors to inject and run scripts, potentially leading to data theft or unauthorized actions. Given the absence of a patch, the risk is heightened despite the SVRS score of 30, indicating a lower risk compared to critical vulnerabilities that require immediate action, this vulnerability can lead to significant compromise. It is critical to monitor for updates or alternative mitigations, especially with the CWE-79 classification. Organizations should be aware of this potential risk within their browser extension ecosystem. This highlights the risks associated with browser extensions.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.