VendorsUrlchatboxchat_anywhere2.4.0
Vulnerabilities

Urlchatbox Chat Anywhere 2.4.0 for Chrome 2.4.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2018-20524
The Chat Anywhere extension 2.4.0 for Chrome allows XSS via crafted use of <<a> in a message, because a danmuWrapper DIV element in chatbox-only\danmu.js is outside the scope of a Content Security Policy (CSP).
Published 2018-12-27 · Modified
6.1EPSS 0.007