A cross-site scripting vulnerability (XSS) was introduced in the DeepL Chrome extension with version v1.22.0 due to improper neutralization of input during web page generation. An incomplete fix was released with version v1.22.2. A complete fix was released with version 1.23.0.
The extension failed to properly sanitize user-controlled input (such as search queries or page content) before rendering it into the DOM. This allows for the execution of arbitrary JavaScript in the context of the user's browser.
A cross-site scripting vulnerability (XSS) was introduced in the DeepL Chrome extension with version v1.22.0 due to improper neutralization of input during web page generation. An incomplete fix was released with version v1.22.2. A complete fix was released with version 1.23.0.
The extension failed to properly sanitize user-controlled input (such as search queries or page content) before rendering it into the DOM. This allows for the execution of arbitrary JavaScript in the context of the user's browser.