ZeroHour

CVE-2018-12587

CVSS 3.0
6.1 medium
EPSS
<1%p55
Published
()
Modified
Description

A cross-site scripting (XSS) vulnerability was found in valeuraddons German Spelling Dictionary v1.3 (an Opera Browser add-on). Instead of providing text for a spelling check, remote attackers may inject arbitrary web script or HTML via the ajax query parameter in the URL Address Bar.

Vendors
german spelling dictionary project
Products
german spelling dictionary
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.