Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9f37-2v5p-xv7g

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Opera before 10.01 does not properly restrict HTML in a (1) RSS or (2) Atom feed, which allows remote attackers to conduct cross-site scripting (XSS) attacks, and conduct cross-zone scripting attacks involving the Feed Subscription Page to read feeds or create feed subscriptions, via a crafted feed, related to the rendering of the application/rss+xml content type as "scripted content."

Opera before 10.01 does not properly restrict HTML in a (1) RSS or (2) Atom feed, which allows remote attackers to conduct cross-site scripting (XSS) attacks, and conduct cross-zone scripting attacks involving the Feed Subscription Page to read feeds or create feed subscriptions, via a crafted feed, related to the rendering of the application/rss+xml content type as "scripted content."

EPSS

Процентиль: 73%
0.00795
Низкий

Дефекты

CWE-79

Связанные уязвимости

nvd
больше 16 лет назад

Opera before 10.01 does not properly restrict HTML in a (1) RSS or (2) Atom feed, which allows remote attackers to conduct cross-site scripting (XSS) attacks, and conduct cross-zone scripting attacks involving the Feed Subscription Page to read feeds or create feed subscriptions, via a crafted feed, related to the rendering of the application/rss+xml content type as "scripted content."

EPSS

Процентиль: 73%
0.00795
Низкий

Дефекты

CWE-79