Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hg35-v9mq-mjhp

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Opera for Android before 54.0.2669.49432 is vulnerable to a sandboxed cross-origin iframe bypass attack. By using a service working inside a sandboxed iframe it is possible to bypass the normal sandboxing attributes. This allows an attacker to make forced redirections without any user interaction from a third-party context.

Opera for Android before 54.0.2669.49432 is vulnerable to a sandboxed cross-origin iframe bypass attack. By using a service working inside a sandboxed iframe it is possible to bypass the normal sandboxing attributes. This allows an attacker to make forced redirections without any user interaction from a third-party context.

EPSS

Процентиль: 14%
0.00045
Низкий

Связанные уязвимости

CVSS3: 5.5
nvd
около 6 лет назад

Opera for Android before 54.0.2669.49432 is vulnerable to a sandboxed cross-origin iframe bypass attack. By using a service working inside a sandboxed iframe it is possible to bypass the normal sandboxing attributes. This allows an attacker to make forced redirections without any user interaction from a third-party context.

EPSS

Процентиль: 14%
0.00045
Низкий