An issue in CSS Exfil Protection v.1.1.0 allows a remote attacker to obtain sensitive information via the content.js and parseCSSRules functions.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://github.com/mlgualtieri/CSS-Exfil-Protection/issues/41 | issue tracking exploit vendor advisory |
https://github.com/randshell/vulnerability-research/tree/main/CVE-2024-29384 | exploit third party advisory |