← Back

CVE-2022-28795

nvd nist
Published: Apr 12, 2022Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

A vulnerability within the Avira Password Manager Browser Extensions provided a potential loophole where, if a user visited a page crafted by an attacker, the discovered vulnerability could trigger the Password Manager Extension to fill in the password field automatically. An attacker could then access this information via JavaScript. The issue was fixed with the browser extensions version 2.18.5 for Chrome, MS Edge, Opera, Firefox, and Safari.

Affected (5)

1 product
Password Manager
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Avira
Version 2.18.4.38471
Version 2.18.4.3847
Version 2.18.4.3847
Version 2.18.4.3868
Version 2.18.4

References (2)

Source: security@nortonlifelock.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.