PT-2016-3426 · Yandex · Yandex Browser
Publicado
2016-10-26
·
Atualizado
2016-12-02
·
CVE-2016-8504
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Yandex Browser versions prior to 16.6
Description
The issue is related to a CSRF vulnerability in the synchronization form of Yandex Browser, which could be exploited by a remote attacker to steal saved data in the browser profile. This vulnerability is associated with a flaw in the browser's synchronization mechanism that allows for cross-site request forgery (CSRF) attacks, enabling a remote attacker to perform unauthorized actions.
Recommendations
For versions prior to 16.6, update to version 16.6 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive browser data to minimize the risk of exploitation.
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Yandex Browser