Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2022-26905

Опубликовано: 31 мая 2022
Источник: msrc
CVSS3: 4.3
EPSS Низкий

Описание

Microsoft Edge (Chromium-based) Spoofing Vulnerability

FAQ

According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?

This vulnerability requires that a user have multiple browser instances open of the affected version of Microsoft Edge (Chromium-based), one of which is a specially crafted website hosted by the attacker. The user would need to access the URL of the malicious website and then click a popup displayed on that site.

What is the version information for this release?

Microsoft Edge VersionDate ReleasedBased on Chromium Version
102.0.1245.305/31/2022102.0.5005.61

According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of integrity (I:L)? What does that mean for this vulnerability?

The user would need to access the URL of the malicious website, which could spoof the content of a legitimate website, and then click a popup displayed on that site.

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

EPSS

Процентиль: 76%
0.00984
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
больше 3 лет назад

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVSS3: 4.3
github
больше 3 лет назад

Microsoft Edge (Chromium-based) Spoofing Vulnerability.

CVSS3: 4.3
fstec
больше 3 лет назад

Уязвимость браузера Microsoft Edge, связанная с ошибками представления информации пользовательским интерфейсом, позволяющая нарушителю проводить спуфинг-атаки

EPSS

Процентиль: 76%
0.00984
Низкий

4.3 Medium

CVSS3