PT-2020-19577 · Danyil Vasilenko · Boat Browser
Rafay Baloch
·
Published
2020-10-20
·
Updated
2020-10-21
·
CVE-2020-7370
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Bolt Browser versions 1.4 and prior
Description
The issue allows an attacker to obfuscate the true source of data as presented in the browser due to a User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of Danyil Vasilenko's Bolt Browser.
Recommendations
For Bolt Browser versions 1.4 and prior, update to a version later than 1.4 to resolve the issue.
Exploit
Fix
Missing Authentication
UI Misrepresentation of Critical Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Boat Browser