CVE Published: 12/07/2018 |
CVE Updated: 05/08/2024 |
CVE Year: 2018 Source: redhat |
Vendor: qutebrowser |
Product: cross-site request forgery flaw allows sites to access \'qute Status : PUBLISHED
CVE-2018-10895 Description
qutebrowser before version 1.4.1 is vulnerable to a cross-site request forgery flaw that allows websites to access \'qute://*\' URLs. A malicious website could exploit this to load a \'qute://settings/set\' URL, which then sets \'editor.command\' to a bash script, resulting in arbitrary code execution.