PT-2016-3426 · Yandex · Yandex Browser

Publicado

2016-10-26

·

Atualizado

2016-12-02

·

CVE-2016-8504

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Yandex Browser versions prior to 16.6
Description The issue is related to a CSRF vulnerability in the synchronization form of Yandex Browser, which could be exploited by a remote attacker to steal saved data in the browser profile. This vulnerability is associated with a flaw in the browser's synchronization mechanism that allows for cross-site request forgery (CSRF) attacks, enabling a remote attacker to perform unauthorized actions.
Recommendations For versions prior to 16.6, update to version 16.6 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive browser data to minimize the risk of exploitation.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-03575
CVE-2016-8504

Produtos afetados

Yandex Browser