CVE-2019-14551
03.08.2019, 02:15
Das Q before 2019-08-02 allows web sites to execute arbitrary code on client machines, as demonstrated by a cross-origin /install request with an attacker-controlled releaseUrl, which triggers download and execution of code within a ZIP archive.
Vendor | Product | Version |
---|---|---|
daskeyboard | das_q_software | 𝑥 < 3.2.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration