GHSA-fgp6-8g62-qx6w
UNKNOWNAll versions of smartsearchwp contain malicious code. The package is malware intended to steal credentials from websites it is loaded in. It traverses DOM elements looking for fields such as username and password and uploads it to a remote server. The package also port-scans the local gateway and uploads the information to the remote server. It has a feature to fetch commands from the remote serve
- Affected
- >=0
- Fixed in
- not stated
- Weakness
- CWE-506
- Published
- 2020-09-03
- Source
- osv