SnowHaze before 2.6.6 is sometimes too late to honor a per-site JavaScript blocking setting, which leads to unintended JavaScript execution via a chain of webpage redirections targeted to the user's browser configuration.
References
Link | Resource |
---|---|
https://snowhaze.com/ssa.txt | Vendor Advisory |
Configurations
Information
Published : 2019-11-13 19:15
Updated : 2021-07-21 04:39
NVD link : CVE-2019-18949
Mitre link : CVE-2019-18949
JSON object : View
CWE
CWE-863
Incorrect Authorization
Products Affected
snowhaze
- snowhaze