A cross-site scripting (XSS) vulnerability was found in valeuraddons German Spelling Dictionary v1.3 (an Opera Browser add-on). Instead of providing text for a spelling check, remote attackers may inject arbitrary web script or HTML via the ajax query parameter in the URL Address Bar.
Advisories
Source ID Title
EUVD EUVD EUVD-2018-4546 A cross-site scripting (XSS) vulnerability was found in valeuraddons German Spelling Dictionary v1.3 (an Opera Browser add-on). Instead of providing text for a spelling check, remote attackers may inject arbitrary web script or HTML via the ajax query parameter in the URL Address Bar.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T08:38:06.308Z

Reserved: 2018-06-19T00:00:00

Link: CVE-2018-12587

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-08-13T17:29:00.857

Modified: 2024-11-21T03:45:29.433

Link: CVE-2018-12587

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.