CVE-2017-7325: Input Validation
Published Jan 19, 2018
·Updated
Yandex Browser before 16.9.0 allows remote attackers to spoof the address bar via window.open.
Affected Software
1 affected component
Yandex Yandex Browser<16.9.0
Event History
Jan 19, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-7325?
CVE-2017-7325 has been classified as a high severity vulnerability due to its potential to allow spoofing of the address bar.
2
How do I fix CVE-2017-7325?
To mitigate CVE-2017-7325, users should update Yandex Browser to version 16.9.0 or later.
3
What type of attack does CVE-2017-7325 enable?
CVE-2017-7325 enables remote attackers to spoof the address bar, which can mislead users regarding the safety of the site.
4
Which versions of Yandex Browser are affected by CVE-2017-7325?
CVE-2017-7325 affects all versions of Yandex Browser prior to 16.9.0.
5
Is CVE-2017-7325 a client-side or server-side vulnerability?
CVE-2017-7325 is a client-side vulnerability, impacting the user's browser experience.