Quantcast
Channel: /dev/posts/
Viewing all articles
Browse latest Browse all 104

Cross-origin/same-site request forgery to RCE in chromedriver

$
0
0

I found a cross-origin/same-site request forgery vulnerability in chromedriver. It was rejected (won't fix) because it is only possible to trigger this from the cross-origin/same-site and not cross-site. In practice, it means it is really only possible to trigger this from another localhost-bound web application.


Viewing all articles
Browse latest Browse all 104

Trending Articles