CVE-2016-5130
MEDIUMGoogle Chrome < 51.0.2704.106 - Improper Access Control
Title source: ruleDescription
content/renderer/history_controller.cc in Google Chrome before 52.0.2743.82 does not properly restrict multiple uses of a JavaScript forward method, which allows remote attackers to spoof the URL display via a crafted web site.
References (15)
Scores
CVSS v3
6.5
EPSS
0.0113
EPSS Percentile
78.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Classification
CWE
CWE-284
Status
draft
Affected Products (1)
google/chrome
< 51.0.2704.106
Timeline
Published
Jul 23, 2016
Tracked Since
Feb 18, 2026