Описание
A remote web page could inject arbitrary HTML code into the Oculus Browser UI, allowing an attacker to spoof UI and potentially execute code. This affects the Oculus Browser starting from version 5.2.7 until 5.7.11.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 5.2.7 (включая) до 5.7.11 (включая)
cpe:2.3:a:oculus:oculus_browser:*:*:*:*:*:*:*:*
EPSS
Процентиль: 58%
0.00371
Низкий
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-74
CWE-79
Связанные уязвимости
CVSS3: 6.1
github
больше 3 лет назад
A remote web page could inject arbitrary HTML code into the Oculus Browser UI, allowing an attacker to spoof UI and potentially execute code. This affects the Oculus Browser starting from version 5.2.7 until 5.7.11.
EPSS
Процентиль: 58%
0.00371
Низкий
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-74
CWE-79