Evernote Chrome²å¼þXSS·ì϶°²È«¹«¸æ,Íþв°²È«¹«¸æ,°²È«×êÑÐ
°ä²¼¹¦·ò 2019-06-14·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-12592£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
ºÏÓÃÓÚEvernoteµÄChrome²å¼þ£¨Evernote Web Clipper£© < 7.11.1¡£
·ì϶¸ÅÊö
Evernote Web ClipperÊÇÒ»¿îä¯ÀÀÆ÷²å¼þ£¬ËüÊÇÓÐÓ¡Ïó±Ê¼ÇEvernoteÍÆ³öµÄÒ»¿î¼ô²Ø²å¼þ£¬Äܹ»Ò»¼üÕ䲨¸÷ÀàÍøÒ³Í¼ÎÄ£¬²¢ÓÀÔ¶±£Áô½øEvernote¡£Í¬Ê±£¬»¹ÄÜÑ¡Ôñ±£ÁôÍøÒ³ÕýÎÄ¡¢°µ²Ø¸æ°×¡¢Õû¸öÒ³Ãæ¡¢ÍøÒ³½ØÆÁµÈ£¬ÈÃÄãÆ¾¾Ý·ÖÆçÐèÒª£¬Ñ¡Ôñ±£ÁôÄÚÈÝ¡£
EvernoteµÄChrome²å¼þ£¨Evernote Web Clipper£©ÖдæÔÚÒ»¸öÑϳÁµÄXSS·ì϶£¬¿ÉÔÊÐí¹¥»÷Õß½Ó¼ûÓû§ÔÚµÚÈý·½·þÎñÖеÄÃô¸ÐÐÅÏ¢¡£¸Ã·ì϶£¨CVE-2019-12592£©ÊôÓÚ²å¼þÖеıàÂëÂß¼ÃýÎ󣬿ÉÈÆ¹ýä¯ÀÀÆ÷µÄͬԴսÊõ£¬Ê¹µÃ¹¥»÷Õß½Ó¼ûµÚÈý·½·þÎñµÄÃô¸ÐÓû§ÐÅÏ¢£¬Ô̺¬Éí·ÝÑéÖ¤ÐÅÏ¢¡¢²ÆÕþÐÅÏ¢¡¢É罻ýÌå̸ÌìÐÅÏ¢¡¢µç×ÓÓʼþÐÅÏ¢µÈ¡£
·ì϶ÑéÖ¤
POC£ºhttps://guard.io/blog/evernote-universal-xss-vulnerability¡£
½¨¸´½¨Òé
Ŀǰ³§ÉÌÒѰ䲼а汾ÒÔ½¨¸´·ì϶£¬½¨ÒéÓû§¸üÐÂÖÁ7.11.1¼°¸ü¸ß°æ±¾¡£
²Î¿¼Á´½Ó
https://www.bleepingcomputer.com/news/security/critical-flaw-in-evernote-add-on-exposed-sensitive-data-of-millions/


¾©¹«Íø°²±¸11010802024551ºÅ