CVE-2022-24075
Published Mar 17, 2022
Last updated 3 years ago
Overview
- Description
- Whale browser before 3.12.129.18 allowed extensions to replace JavaScript files of the HWP viewer website which could access to local HWP files. When the HWP files were opened, the replaced script could read the files.
- Source
- cve@navercorp.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 6.5
- Impact score
- 3.6
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:N/A:N
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:navercorp:whale:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "47138F1B-655D-4459-905C-7BFA3A326DC5", "versionEndExcluding": "3.12.129.18" } ], "operator": "OR" } ] } ]