CVE-2022-24762 - CVE House
Back to Database
Status published Medium CVE-2022-24762

Exposure of Sensitive Information to an Unauthorized Actor in sysend.js

Vulnerability Description

sysend.js is a library that allows a user to send messages between pages that are open in the same browser. Users that use cross-origin communication may have their communications intercepted. Impact is limited by the communication occurring in the same browser. This issue has been patched in sysend.js version 1.10.0. The only currently known workaround is to avoid sending communications that a user does not want to have intercepted via sysend messages.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-24762

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

sysend.js
Vulnerable Versions:
< 1.10.0

Timeline

Official Publish: March 14th, 2022
Last Modified: September 18th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Weaknesses (CWE)