Description
Whale browser before 3.12.129.18 allowed extensions to replace JavaScript files of the HWP viewer website which could access to local HWP files. When the HWP files were opened, the replaced script could read the files.
References
https://cve.naver.com/detail/cve-2022-24075
Vendor Advisory
https://cve.naver.com/detail/cve-2022-24075
Vendor Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
6.5 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2022-03-17T05:15:06.950Z
3 years agoLast modified
2024-11-21T05:49:46.480Z
1 year ago