Microsoft Edge Content Security...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Summary An exploitable information leak vulnerability exists in the Content Security Policy enforcement functionality of Microsoft Edge 40.15063.0.0. A specially crafted web page can cause a content security policy bypass resulting in an information leak. An attacker can create a malicious webpage to trigger this vulnerability. ### Tested Versions Microsoft Edge 40.15063.0.0 ### Product URLs https://www.microsoft.com/en-us/windows/microsoft-edge ### CVSSv3 Score 4.3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N ### CWE CWE-284: Improper Access Control ### Details An attacker can bypass the Content-Security-Policy header that is used to make the browser protect against information leakage from a web site. By loading a new document using window.open("","_blank") and document.write-ing into it, (being in about:blank) an attacker can circumvent the CSP restrictions put on the document that the original page's Javascript code was running on and reach out to other sites. One could...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息