Vulnerability · NVD
CVE-2020-6159
CVE-2020-6159, medium severity (CVSS 6.1): 1 tracked app concerned, all fixed or indeterminable on their current version.
- Severity (CVSS)
- 6.1
- Exploitation
- 0.6 %
- Tracked apps
- 1
- Still exposed
- 0
NVD scale
EPSS, predicted over 30 days
URLs using “javascript:” have the protocol removed when pasted into the address bar to protect users from cross-site scripting (XSS) attacks, but in certain circumstances this removal was not performed. This could allow users to be socially engineered to run an XSS attack against themselves. This vulnerability affects Opera for Android versions below 61.0.3076.56532.
Show raw CVSS vector
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
-
Observed affected builds (6)
Vulnerable CPE configurations (1)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
| opera |
opera Android
|
Android | <61.0.3076.56532 | cpe:2.3:a:opera:opera:*:*:*:*:*:android:*:* |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.