Evernote.Web.Clipper.FrameSerializer.js.XSS
Description
This indicates an attempt to exploit a Cross-site Scripting Vulnerability in Evernote Webclipper Extension for Chrome.
A remote, unauthenticated attacker can exploit this vulnerability by sending a crafted request to the target server. Successful exploitation results in the execution of arbitrary script code in the browser.
Affected Products
Evernote Web Clipper extension for Chrome prior to 7.11.1
Impact
System Compromise : Remote attackers can execute arbitrary script code within the context of the target user's browser
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
https://chrome.google.com/webstore/detail/evernote-web-clipper/pioclpoplcdbaefihamjohnefbikjilc?hl=en
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |