PT-2018-5813 · Google+3 · Google Chrome+3

Junaid Farhan

·

Published

2017-12-07

·

Updated

2024-06-15

·

CVE-2017-15427

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Google Chrome versions prior to 63.0.3239.84
Description: The issue is related to insufficient policy enforcement in Omnibox, allowing a socially engineered user to perform a self-XSS attack by dragging and dropping a javascript: URL into the URL bar.
Recommendations: For versions prior to 63.0.3239.84, update to version 63.0.3239.84 or later to resolve the issue.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2813
CVE-2017-15427
DSA-4064-1
OPENSUSE-SU-2017:3245-1
OPENSUSE-SU-2017_3244-1
OPENSUSE-SU-2024:10681-1
OPENSUSE-SU-2024:12948-1
RHSA-2017:3401
RHSA-2017_3401

Affected Products

Alt Linux
Google Chrome
Red Hat
Suse