Whale browser before 3.12.129.18 allowed extensions to replace JavaScript files of the HWP viewer website which could access to local HWP files. When the HWP files were opened, the replaced script could read the files.
References
Link | Resource |
---|---|
https://cve.naver.com/detail/cve-2022-24075 | Vendor Advisory |
https://cve.naver.com/detail/cve-2022-24075 | Vendor Advisory |
Configurations
History
21 Nov 2024, 06:49
Type | Values Removed | Values Added |
---|---|---|
References | () https://cve.naver.com/detail/cve-2022-24075 - Vendor Advisory |
Information
Published : 2022-03-17 06:15
Updated : 2024-11-21 06:49
NVD link : CVE-2022-24075
Mitre link : CVE-2022-24075
CVE.ORG link : CVE-2022-24075
JSON object : View
Products Affected
navercorp
- whale
CWE
CWE-552
Files or Directories Accessible to External Parties