CVE-2017-5124
MEDIUMGoogle Chrome < 62.0.3202.62 - Universal Cross-Site Scripting via MHTML Page
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2017-5124. PoCs published by Anton Lopanitsyn, Bo0oM.
AI-analyzed exploit summary This exploit leverages CVE-2017-5124, a vulnerability in Chrome's handling of MHTML files, to execute arbitrary JavaScript in the context of a different origin. The PoC uses a multipart MHTML file with an embedded XSL stylesheet to bypass same-origin policy restrictions.
Description
Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted MHTML page.
Exploits (2)
This exploit leverages CVE-2017-5124, a vulnerability in Chrome's handling of MHTML files, to execute arbitrary JavaScript in the context of a different origin. The PoC uses a multipart MHTML file with an embedded XSL stylesheet to bypass same-origin policy restrictions.
This PoC demonstrates a Universal Cross-Site Scripting (UXSS) vulnerability in Chrome via MHTML. The PHP script serves a malicious MHTML file, exploiting improper handling of multipart/related content to achieve script execution in the context of another site.
References (9)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N