Vulnerability Description
The Video Downloader professional extension before 2018-04-05 for Chrome has Universal XSS (UXSS) via vectors related to a link64_msgAddLinks event.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Videodownloaderultimate | Video Downloader | < 2018-04-05 |
Related Weaknesses (CWE)
References
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1555Issue Tracking
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1555Issue Tracking
FAQ
What is CVE-2018-10000?
CVE-2018-10000 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The Video Downloader professional extension before 2018-04-05 for Chrome has Universal XSS (UXSS) via vectors related to a link64_msgAddLinks event.
How severe is CVE-2018-10000?
CVE-2018-10000 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-10000?
Check the references section above for vendor advisories and patch information. Affected products include: Videodownloaderultimate Video Downloader.