URLs using “javascript:” have the protocol removed when pasted into the address bar to protect users from cross-site scripting (XSS) attacks, but in certain circumstances this removal was not performed. This could allow users to be socially engineered to run an XSS attack against themselves. This vulnerability affects Opera for Android versions below 61.0.3076.56532.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Opera
Published: 2020-12-23T15:08:58
Updated: 2024-08-04T08:55:21.884Z
Reserved: 2020-01-07T00:00:00
Link: CVE-2020-6159
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-12-23T16:15:13.093
Modified: 2024-11-21T05:35:13.073
Link: CVE-2020-6159
Redhat
No data.