
We found results for “”
WS-2019-0480
Good to know:

Date: January 25, 2019
Stream-combine v2.0.2 contains malicious code design to steal credentials and credit card information. The code searches all form elements for passwords, credit card numbers and CVC codes. It then uploads the information to a remote server (if your application has Content Security Policy set you are not affected by this issue).
Language: JS
Severity Score
Severity Score
Weakness Type (CWE)
Code
CWE-17Top Fix

Upgrade Version
No fix version available
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | CHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | LOW |
Availability (A): | NONE |