Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-84051
HistoryMar 21, 2022 - 12:00 a.m.

Naver Whale Browser Cross-Site Scripting Vulnerability

2022-03-2100:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
naver whale browser
cross-site scripting
vulnerability
data validation
devtools.inspectedwindow

EPSS

0.001

Percentile

31.3%

A cross-site scripting vulnerability exists in versions prior to 3.12.129.18 of Naver Whale Browser, a web browser from Naver Korea that supports user-defined interfaces, due to a lack of data validation filtering of user-supplied and output data. An attacker could exploit this to allow extension developers to inject arbitrary JavaScript into extension store pages via devtools.inspectedWindow.

EPSS

0.001

Percentile

31.3%

Related for CNVD-2022-84051