SnowHaze before 2.6.6 is sometimes too late to honor a per-site JavaScript blocking setting, which leads to unintended JavaScript execution via a chain of webpage redirections targeted to the user's browser configuration.
References
Link | Resource |
---|---|
https://snowhaze.com/ssa.txt | Vendor Advisory |
https://snowhaze.com/ssa.txt | Vendor Advisory |
Configurations
History
21 Nov 2024, 04:33
Type | Values Removed | Values Added |
---|---|---|
References | () https://snowhaze.com/ssa.txt - Vendor Advisory |
Information
Published : 2019-11-14 03:15
Updated : 2024-11-21 04:33
NVD link : CVE-2019-18949
Mitre link : CVE-2019-18949
CVE.ORG link : CVE-2019-18949
JSON object : View
Products Affected
snowhaze
- snowhaze
CWE
CWE-863
Incorrect Authorization