CVE-2022-28795 Information
Jun 07, 2022
cve
Description
A vulnerability within the Avira Password Manager Browser Extensions provided a potential loophole where if a user visited a page crafted by an attacker the discovered vulnerability could trigger the Password Manager Extension to fill in the password field automatically. An attacker could then access this information via JavaScript. The issue was fixed with the browser extensions version 2.18.5 for Chrome MS Edge Opera Firefox and Safari.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Reference
https://support.norton.com/sp/static/external/tools/security-advisories.html
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
6.5
Share on: