PT-2018-1653 · Microsoft · Internet Explorer 11+1

Masato Kinugawa

·

Published

2018-09-11

·

Updated

2018-11-09

·

CVE-2018-8470

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Internet Explorer 11
Description A security feature bypass issue exists due to how scripts are handled, allowing a universal cross-site scripting (UXSS) condition. This could enable a remote attacker to perform a cross-site scripting attack using a specially crafted web page, potentially accessing any session belonging to web pages currently opened or cached by the browser.
Recommendations For Internet Explorer 11, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-01212
CVE-2018-8470

Affected Products

Internet Explorer
Internet Explorer 11