Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0140.
References
Configurations
History
21 Nov 2024, 03:02
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/96656 - | |
References | () http://www.securitytracker.com/id/1038006 - | |
References | () https://medium.com/bugbountywriteup/bypass-csp-by-abusing-xss-filter-in-edge-43e9106a9754 - | |
References | () https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0135 - Patch, Vendor Advisory | |
References | () https://www.freebuf.com/articles/web/164871.html - |
Information
Published : 2017-03-17 00:59
Updated : 2024-11-21 03:02
NVD link : CVE-2017-0135
Mitre link : CVE-2017-0135
CVE.ORG link : CVE-2017-0135
JSON object : View
Products Affected
microsoft
- edge
CWE