We found results for “”
WS-2019-0480
Date: January 25, 2019
Stream-combine v2.0.2 contains malicious code design to steal credentials and credit card information. The code searches all form elements for passwords, credit card numbers and CVC codes. It then uploads the information to a remote server (if your application has Content Security Policy set you are not affected by this issue).
Language: JS
Severity Score
Related Resources (2)
Severity Score
Weakness Type (CWE)
Code
CWE-17CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | CHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | LOW |
Availability (A): | NONE |