An issue in CSS Exfil Protection v.1.1.0 allows a remote attacker to obtain sensitive information due to missing support for CSS variables
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://github.com/mlgualtieri/CSS-Exfil-Protection/issues/41 | issue tracking exploit vendor advisory |
https://github.com/randshell/vulnerability-research/tree/main/CVE-2024-33436 | exploit third party advisory |