CVE-2017-0135 Information
Feb 14, 2021
cve
Description
Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows aka \Microsoft Edge Security Feature Bypass Vulnerability.\ This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0140.
CVSS Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Reference
http://www.securityfocus.com/bid/96656 http://www.securitytracker.com/id/1038006 https://medium.com/bugbountywriteup/bypass-csp-by-abusing-xss-filter-in-edge-43e9106a9754 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0135 https://www.freebuf.com/articles/web/164871.html
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
4.2
Share on: