Vulnerability Description
Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that redirects to a child tab and rewrites the innerHTML property.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Samsung | Internet Browser | 5.4.02.3 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/145510/Samsung-Internet-Browser-SOP-Bypass.ExploitThird Party AdvisoryVDB Entry
- https://datarift.blogspot.in/p/samsung-interent-browser-sop-bypass-cve.htmlExploitThird Party Advisory
- https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gatExploitThird Party Advisory
- https://www.exploit-db.com/exploits/43376/ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/145510/Samsung-Internet-Browser-SOP-Bypass.ExploitThird Party AdvisoryVDB Entry
- https://datarift.blogspot.in/p/samsung-interent-browser-sop-bypass-cve.htmlExploitThird Party Advisory
- https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gatExploitThird Party Advisory
- https://www.exploit-db.com/exploits/43376/ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2017-17692?
CVE-2017-17692 is a vulnerability with a CVSS score of 7.5 (HIGH). Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that redirects to a child tab and rewrites the i...
How severe is CVE-2017-17692?
CVE-2017-17692 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-17692?
Check the references section above for vendor advisories and patch information. Affected products include: Samsung Internet Browser.