Description
core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 33.0.1750.117, inserts the about:blank URL during certain blocking of FORM elements within HTTP requests, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via unspecified vectors.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2883-1 | chromium-browser security update |
EUVD |
EUVD-2013-6459 | core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 33.0.1750.117, inserts the about:blank URL during certain blocking of FORM elements within HTTP requests, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via unspecified vectors. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T17:46:22.383Z
Reserved: 2013-11-05T00:00:00.000Z
Link: CVE-2013-6657
No data.
Status : Modified
Published: 2014-02-24T04:48:10.053
Modified: 2026-04-29T01:13:23.040
Link: CVE-2013-6657
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD