vendor:
Opera Browser
by:
5.3
CVSS
MEDIUM
Same Origin Policy Bypass
79
CWE
Product Name: Opera Browser
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: a:opera:opera_browser
Platforms Tested: Windows, Linux
Same Origin Policy Bypass in Opera Browser
The vulnerability allows an attacker to bypass the same origin policy in some versions of the Opera Browser. By modifying the location property of an IFRAME or FRAME included in the document, an attacker can execute script code within the context of the previous frame site. This can lead to potential information disclosure or unauthorized actions.
Mitigation:
Upgrade to a fixed version of the Opera Browser. Avoid loading untrusted or unknown websites within frames.