PT-2020-18971 · Opera · Opera

Published

2020-12-23

·

Updated

2020-12-23

·

CVE-2020-6159

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Opera for Android versions below 61.0.3076.56532
Description The issue arises when URLs using javascript: are pasted into the address bar. Normally, the protocol is removed to protect against cross-site scripting (XSS) attacks. However, in certain circumstances, this removal does not occur, potentially allowing users to be socially engineered into running an XSS attack against themselves.
Recommendations For Opera for Android versions below 61.0.3076.56532, update to version 61.0.3076.56532 or later to resolve the issue. As a temporary workaround, consider avoiding the use of javascript: URLs in the address bar until the update is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-6159

Affected Products

Opera