CVE-2016-5165 — Cross-site Scripting in Google Chrome
Severity
6.1MEDIUMNVD
OSV7.5
EPSS
0.4%
top 37.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 11
Latest updateMay 14
Description
Cross-site scripting (XSS) vulnerability in the Developer Tools (aka DevTools) subsystem in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux allows remote attackers to inject arbitrary web script or HTML via the settings parameter in a chrome-devtools-frontend.appspot.com URL's query string.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7
Affected Packages2 packages
🔴Vulnerability Details
4GHSA▶
GHSA-2rw9-q6xx-mmw5: Cross-site scripting (XSS) vulnerability in the Developer Tools (aka DevTools) subsystem in Google Chrome before 53↗2022-05-14
OSV▶
CVE-2016-5165: Cross-site scripting (XSS) vulnerability in the Developer Tools (aka DevTools) subsystem in Google Chrome before 53↗2016-09-02
VulnCheck▶
Google Chrome Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')↗2016