← Back to CVE List

CVE-2018-6654

Published: 2018-02-06T01:29Z
Last Modified: 2024-11-21T04:11Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The Grammarly extension before 2018-02-02 for Chrome allows remote attackers to discover authentication tokens via an 'action: "user"' request to iframe.gr_-ifr, because the exposure of these tokens is not restricted to any specific web site. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt