Fiche vulnérabilité
CVE-2021-20791 : faille critique jscom revoworks browser (CVSS 9.3)
Description
Improper access control vulnerability in RevoWorks Browser 2.1.230 and earlier allows an attacker to bypass access restriction and to exchange unauthorized files between the local environment and the isolated environment or settings of the web browser via unspecified vectors.
En bref
- Sévérité
- Critique (CVSS 9.3)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 17 sept. 2021
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- jscom revoworks browser