PT-2020-18971 · Opera · Opera
Published
2020-12-23
·
Updated
2020-12-23
·
CVE-2020-6159
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Opera for Android versions below 61.0.3076.56532
Description
The issue arises when URLs using
javascript: are pasted into the address bar. Normally, the protocol is removed to protect against cross-site scripting (XSS) attacks. However, in certain circumstances, this removal does not occur, potentially allowing users to be socially engineered into running an XSS attack against themselves.Recommendations
For Opera for Android versions below 61.0.3076.56532, update to version 61.0.3076.56532 or later to resolve the issue. As a temporary workaround, consider avoiding the use of
javascript: URLs in the address bar until the update is applied.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opera