CVE-2026-2345 - CERT CVE
ID CVE-2026-2345
Sažetak Proctorio Chrome Extension is a browser extension used for online proctoring. The extension contains multiple window.addEventListener('message', ...) handlers that do not properly validate the origin of incoming messages. Specifically, an internal messaging bridge processes messages based solely on the presence of a fromWebsite property without verifying the event.origin attribute.
Reference
CVSS
Base: 3.6
Impact: 2.5
Exploitability:1.0
Pristup
VektorSloženostAutentikacija
LOCAL HIGH NONE
Impact
PovjerljivostCjelovitostDostupnost
LOW LOW NONE
CVSS vektor CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Zadnje važnije ažuriranje 11-02-2026 - 15:27
Objavljeno 11-02-2026 - 15:16