EIP-2026-103839
PRE-CVEAdobe SVG Viewer 3.0 - 'postURL'/'getURL' Restriction Bypass
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-103839. PoCs published by GreyMagic Software.
AI-analyzed exploit summary The code describes a vulnerability in Adobe SVG Viewer (ASV) 3.0 and prior, where the getURL() and postURL() methods can bypass domain restrictions via redirects, leading to local/remote file access or cookie theft. The provided snippet demonstrates the exploit concept but lacks functional exploit code.
Description
Adobe SVG Viewer 3.0 - 'postURL'/'getURL' Restriction Bypass
Exploits (1)
The code describes a vulnerability in Adobe SVG Viewer (ASV) 3.0 and prior, where the getURL() and postURL() methods can bypass domain restrictions via redirects, leading to local/remote file access or cookie theft. The provided snippet demonstrates the exploit concept but lacks functional exploit code.