Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cffp-gwjx-w2q2

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Opera before 11.62 allows remote attackers to bypass the Same Origin Policy via the (1) history.pushState and (2) history.replaceState functions in conjunction with cross-domain frames, leading to unintended read access to history.state information.

Opera before 11.62 allows remote attackers to bypass the Same Origin Policy via the (1) history.pushState and (2) history.replaceState functions in conjunction with cross-domain frames, leading to unintended read access to history.state information.

EPSS

Процентиль: 69%
0.0061
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
почти 14 лет назад

Opera before 11.62 allows remote attackers to bypass the Same Origin Policy via the (1) history.pushState and (2) history.replaceState functions in conjunction with cross-domain frames, leading to unintended read access to history.state information.

EPSS

Процентиль: 69%
0.0061
Низкий

Дефекты

CWE-200