CVE-2010-2301: XSS
Cross-site scripting (XSS) vulnerability in editing/markup.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to inject arbitrary web script or HTML via vectors related to the node.innerHTML property of a TEXTAREA element. NOTE: this might overlap CVE-2010-1762.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2301?
CVE-2010-2301 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2010-2301?
To fix CVE-2010-2301, update Google Chrome to version 5.0.375.70 or later.
Which versions of Google Chrome are affected by CVE-2010-2301?
CVE-2010-2301 affects Google Chrome versions earlier than 5.0.375.70.
What is the nature of the vulnerability in CVE-2010-2301?
CVE-2010-2301 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary scripts into a web page.
Are there any other software affected by CVE-2010-2301?
Yes, CVE-2010-2301 also affects certain versions of openSUSE and SUSE Linux Enterprise Desktop and Server.