Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7q7r-w4pq-v5q2

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

android/java/src/org/chromium/chrome/browser/WebsiteSettingsPopup.java in Google Chrome before 43.0.2357.65 on Android does not properly restrict use of a URL's fragment identifier during construction of a page-info popup, which allows remote attackers to spoof the URL bar or deliver misleading popup content via crafted text.

android/java/src/org/chromium/chrome/browser/WebsiteSettingsPopup.java in Google Chrome before 43.0.2357.65 on Android does not properly restrict use of a URL's fragment identifier during construction of a page-info popup, which allows remote attackers to spoof the URL bar or deliver misleading popup content via crafted text.

EPSS

Процентиль: 77%
0.01064
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 10 лет назад

android/java/src/org/chromium/chrome/browser/WebsiteSettingsPopup.java in Google Chrome before 43.0.2357.65 on Android does not properly restrict use of a URL's fragment identifier during construction of a page-info popup, which allows remote attackers to spoof the URL bar or deliver misleading popup content via crafted text.

redhat
больше 10 лет назад

android/java/src/org/chromium/chrome/browser/WebsiteSettingsPopup.java in Google Chrome before 43.0.2357.65 on Android does not properly restrict use of a URL's fragment identifier during construction of a page-info popup, which allows remote attackers to spoof the URL bar or deliver misleading popup content via crafted text.

nvd
больше 10 лет назад

android/java/src/org/chromium/chrome/browser/WebsiteSettingsPopup.java in Google Chrome before 43.0.2357.65 on Android does not properly restrict use of a URL's fragment identifier during construction of a page-info popup, which allows remote attackers to spoof the URL bar or deliver misleading popup content via crafted text.

debian
больше 10 лет назад

android/java/src/org/chromium/chrome/browser/WebsiteSettingsPopup.java ...

fstec
больше 10 лет назад

Уязвимость браузера Google Chrome, позволяющая нарушителю подменить данные

EPSS

Процентиль: 77%
0.01064
Низкий

Дефекты

CWE-20