Exploitation Summary
EIP tracks 2 public exploits for CVE-2020-6519. PoCs published by Gal Weizman, PerimeterX.
AI-analyzed exploit summary This exploit demonstrates a full CSP (Content Security Policy) bypass in Chromium 83 by dynamically injecting malicious objects, iframes, and scripts via JavaScript. It leverages a vulnerability in the handling of 'javascript:' URIs in iframes to execute arbitrary code, bypassing CSP restrictions.
Description
Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.
Exploits (2)
This exploit demonstrates a full CSP (Content Security Policy) bypass in Chromium 83 by dynamically injecting malicious objects, iframes, and scripts via JavaScript. It leverages a vulnerability in the handling of 'javascript:' URIs in iframes to execute arbitrary code, bypassing CSP restrictions.
This repository contains a functional proof-of-concept exploit for CVE-2020-6519, a Chromium CSP bypass vulnerability. The exploit leverages a JavaScript iframe injection technique to bypass Content Security Policy restrictions, allowing the execution of scripts from unauthorized sources.
References (11)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N