Vulnerability Management

FP-2023-004-Automa Extension for Chrome Message Handling Universal XSS

Exploitation of this issue allows a universal cross-site scripting attack. If a user visits a specially crafted web page, an attacker can inject JavaScript code into web pages that are embedded via an iframe. The script code executes in the context of the user's browser session within the trust relationship between the browser and the server. The attacker can then access any content on that page or disclose e.g. session cookies to gain direct access to a user account.