Vulnerability CVE-2015-6790: Information

Description

The WebPageSerializerImpl::openTagToString function in WebKit/Source/web/WebPageSerializerImpl.cpp in the page serializer in Google Chrome before 47.0.2526.80 does not properly use HTML entities, which might allow remote attackers to inject arbitrary web script or HTML via a crafted document, as demonstrated by a double-quote character inside a single-quoted string.

Severity: MEDIUM (4.3)

Published: Dec. 14, 2015
Modified: Nov. 7, 2023
Error type identifier: CWE-20

Fixed packages

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
      End including
      47.0.2526.73