The React Developer Tools extension registers a message listener with window.addEventListener('message', <listener>) in a content script that is accessible to any webpage that is active in the browser. Within the listener is code that requests a URL derived from the received message via fetch(). The URL is not validated or sanitised before it is fetched, thus allowing a malicious web page to arbitrarily fetch URL’s via the victim's browser.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: snyk

Published: 2023-10-19T14:28:23.769Z

Updated: 2023-10-19T14:28:23.769Z

Reserved: 2023-10-19T12:33:43.948Z


Link: CVE-2023-5654

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-10-19T15:15:09.973

Modified: 2023-10-27T21:53:06.943


Link: CVE-2023-5654

JSON object: View

cve-icon Redhat Information

No data.