PT-2016-3427 · Yandex · Yandex Browser Translator Extension+1
Published
2016-10-26
·
Updated
2016-12-02
·
CVE-2016-8506
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Yandex browser for desktop versions 15.12 through 16.2
Description
The issue is related to a lack of protection for the web page structure in the Yandex Browser Translator extension, allowing a remote attacker to conduct a cross-site scripting (XSS) attack and evaluate arbitrary JavaScript code.
Recommendations
For versions 15.12 through 16.2, consider disabling the Translator extension until a patch is available to prevent potential XSS attacks. Restrict access to sensitive web pages to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yandex Browser
Yandex Browser Translator Extension