PT-2025-33514 · Unknown · Buttercup Buttercup-Browser-Extension

Published

2025-08-16

·

Updated

2025-08-24

·

CVE-2017-20199

CVSS v2.0
2.6
VectorAV:N/AC:H/Au:N/C:P/I:N/A:N

Name of the Vulnerable Software and Affected Versions:

Buttercup buttercup-browser-extension versions up to 0.14.2

Description:

A vulnerability exists in Buttercup buttercup-browser-extension up to version 0.14.2 due to improper access controls. The issue is remotely exploitable, but the complexity of an attack is high and exploitation appears to be difficult. The exploit has been publicly disclosed. This vulnerability affects products that are no longer supported by the maintainer.

Recommendations:

Upgrade to version 1.0.1 to address this issue.

Fix

Improper Access Control

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2017-20199

Affected Products

Buttercup Buttercup-Browser-Extension