Whale browser before 3.12.129.18 allowed extensions to replace JavaScript files of the HWP viewer website which could access to local HWP files. When the HWP files were opened, the replaced script could read the files.
References
Link | Resource |
---|---|
https://cve.naver.com/detail/cve-2022-24075 | Vendor Advisory |
Configurations
Information
Published : 2022-03-16 23:15
Updated : 2022-03-23 11:52
NVD link : CVE-2022-24075
Mitre link : CVE-2022-24075
JSON object : View
CWE
CWE-552
Files or Directories Accessible to External Parties
Products Affected
navercorp
- whale