Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h89f-7xhx-wfx9

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 33.0.1750.117, inserts the about:blank URL during certain blocking of FORM elements within HTTP requests, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via unspecified vectors.

core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 33.0.1750.117, inserts the about:blank URL during certain blocking of FORM elements within HTTP requests, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via unspecified vectors.

EPSS

Процентиль: 50%
0.00272
Низкий

Связанные уязвимости

ubuntu
почти 12 лет назад

core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 33.0.1750.117, inserts the about:blank URL during certain blocking of FORM elements within HTTP requests, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via unspecified vectors.

nvd
почти 12 лет назад

core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 33.0.1750.117, inserts the about:blank URL during certain blocking of FORM elements within HTTP requests, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via unspecified vectors.

debian
почти 12 лет назад

core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used i ...

EPSS

Процентиль: 50%
0.00272
Низкий