SnowHaze before 2.6.6 is sometimes too late to honor a per-site JavaScript blocking setting, which leads to unintended JavaScript execution via a chain of webpage redirections targeted to the user's browser configuration.
References
Link | Resource |
---|---|
https://snowhaze.com/ssa.txt | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2019-11-14 03:15
Updated : 2024-02-04 20:39
NVD link : CVE-2019-18949
Mitre link : CVE-2019-18949
CVE.ORG link : CVE-2019-18949
JSON object : View
Products Affected
snowhaze
- snowhaze
CWE
CWE-863
Incorrect Authorization