Record summary

CVE-2017-5124 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted MHTML page.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Google Chrome prior to 62.0.3202.62

CVE ListGoogle Chrome prior to 62.0.3202.62affected

Proofs of concept

2

Catalogued exploits

ExploitDBWebkit (Chome < 61) - 'MHTML' Universal Cross-site ScriptingExploitDB exploitby Anton LopanitsynNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubBo0oM/CVE-2017-5124Repository PoCby Bo0oMStars: 160Not analyzed3 files

948 B

GitHub

PoC details

References

10