CVE-2021-36668
12.07.2022, 14:15
URL injection in Driva inSync 6.9.0 for MacOS, allows attackers to force a visit to an arbitrary url via the port parameter to the Electron App.
Vendor | Product | Version |
---|---|---|
druva | insync_client | 𝑥 < 5.9.3 |
druva | insync_client | 𝑥 < 7.0.1 |
druva | insync_client | 𝑥 < 7.0.1 |
𝑥
= Vulnerable software versions
References