6.8
CVSSv2

CVE-2019-9673

Published: 05/06/2019 Updated: 10/06/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Freenet 1483 has a MIME type bypass that allows arbitrary JavaScript execution via a crafted Freenet URI.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

freenetproject freenet 0.7.5

Github Repositories

Writeup

CVE-2019-9673: Freenet content filter vulnerability NOTE: I have fully disclosed this bug to the Freenet team and worked with them to verify their patch The patch is now deployed in the latest version of Freenet I've recently found a security vulnerability in Freenet that may allow an attacker to de-anonymize a target or send malicious documents through Freenet Impact T