PT-2009-6279 · Yoono · Yoono

Nick Freeman

+1

·

Published

2009-11-28

·

Updated

2024-03-12

·

CVE-2009-4100

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Yoono extension versions prior to 6.1.1
Description The issue allows user-assisted remote attackers to execute arbitrary commands and perform cross-domain scripting attacks via DOM event handlers such as onload. This is due to the extension performing certain operations with chrome privileges.
Recommendations For versions prior to 6.1.1, update to version 6.1.1 or later to resolve the issue. As a temporary workaround, consider disabling the Yoono extension until a patch is available.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-4100
ROSA-SA-2024-2370

Affected Products

Yoono