PT-2022-8068 · Unknown · Twitter-Post-Fetcher

Lah7

·

Published

2022-12-29

·

Updated

2024-05-17

·

CVE-2018-25058

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Twitter-Post-Fetcher versions up to 17.x
Description A vulnerability has been found in Twitter-Post-Fetcher, affecting an unknown part of the file js/twitterFetcher.js of the component Link Target Handler. The manipulation leads to the use of a web link to an untrusted target with window.opener access. It is possible to initiate the attack remotely. Upgrading to version 18.0.0 can address this issue.
Recommendations For Twitter-Post-Fetcher versions up to 17.x, upgrade to version 18.0.0 to address the issue. As a temporary workaround, consider restricting access to the js/twitterFetcher.js file until the upgrade is applied.

Fix

Weakness Enumeration

Related Identifiers

CVE-2018-25058
GHSA-M688-CX2P-RGQ9

Affected Products

Twitter-Post-Fetcher