CVE-1999-1549Origin Validation Error in Project Lynx

Severity
7.8HIGHNVD
EPSS
0.2%
top 56.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 16
Latest updateApr 30

Description

Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a "secure" hidden form value from a temporary file and craft a LYNXOPTIONS: URL that causes Lynx to modify the user's configuration file and execute commands.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages1 packages

NVDlynx_project/lynx2.7, 2.8+1

🔴Vulnerability Details

1
GHSA
GHSA-cgjq-p4q9-cfj7: Lynx 22022-04-30

📐Framework References

1
CWE
Origin Validation Error