A critical flaw in the Evernote Web Clipper Chrome extension could allow potential attackers to access users' sensitive information from third party online services.
"Due to Evernote's widespread popularity, this issue had the potential of affecting its consumers and companies who use the extension – about 4,600,000 users at the time of discovery," says security company Guardio which discovered the vulnerability.
The Universal Cross-site Scripting flaw
The security issue is a Universal Cross-site Scripting (UXSS) (aka Universal XSS) tracked as CVE-2019-12592 and stemming from an Evernote Web Clipper logical coding error that made it possible to "bypass the browser's same origin policy, granting the attacker code execution privileges in Iframes beyond Evernote's domain."
... ... ...