Lucene search

K
cvelistChromeCVELIST:CVE-2015-6790
HistoryDec 14, 2015 - 11:00 a.m.

CVE-2015-6790

2015-12-1411:00:00
Chrome
www.cve.org
4

AI Score

8.2

Confidence

High

EPSS

0.005

Percentile

77.2%

The WebPageSerializerImpl::openTagToString function in WebKit/Source/web/WebPageSerializerImpl.cpp in the page serializer in Google Chrome before 47.0.2526.80 does not properly use HTML entities, which might allow remote attackers to inject arbitrary web script or HTML via a crafted document, as demonstrated by a double-quote character inside a single-quoted string.