Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Lah7

#43860of 53,633
6.1Total CVSS
Vulnerabilities · 1
PT-2022-8068
6.1
2022-12-29
Unknown · Twitter-Post-Fetcher · CVE-2018-25058
**Name of the Vulnerable Software and Affected Versions** Twitter-Post-Fetcher versions up to 17.x **Description** A vulnerability has been found in Twitter-Post-Fetcher, affecting an unknown part of the file `js/twitterFetcher.js` of the component Link Target Handler. The manipulation leads to the use of a web link to an untrusted target with `window.opener` access. It is possible to initiate the attack remotely. Upgrading to version 18.0.0 can address this issue. **Recommendations** For Twitter-Post-Fetcher versions up to 17.x, upgrade to version 18.0.0 to address the issue. As a temporary workaround, consider restricting access to the `js/twitterFetcher.js` file until the upgrade is applied.