CVE-2019-9150
09.07.2019, 21:15
Mailvelope prior to 3.3.0 does not require user interaction to import public keys shown on web page. This functionality can be tricked to either hide a key import from the user or obscure which key was imported.Enginsight
Vendor | Product | Version |
---|---|---|
mailvelope | mailvelope | 𝑥 < 3.3.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References