CVE-2016-6908

CWE-601Open Redirect3 documents3 sources
Severity
6.1MEDIUM
EPSS
0.2%
top 60.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 26
Latest updateMay 17

Description

Characters from languages are such as Arabic, Hebrew are displayed from RTL (Right To Left) order in Opera 37.0.2192.105088 for Android, due to mishandling of several unicode characters such as U+FE70, U+0622, U+0623 etc and how they are rendered combined with (first strong character) such as an IP address or alphabet could lead to a spoofed URL. It was noticed that by placing neutral characters such as "/", "?" in filepath causes the URL to be flipped and displayed from Right To Left. However,

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

NVDopera/opera_browser37.0.2192.105088

🔴Vulnerability Details

2
GHSA
GHSA-7xf8-x4wh-25c5: Characters from languages are such as Arabic, Hebrew are displayed from RTL (Right To Left) order in Opera 372022-05-17
CVEList
CVE-2016-6908: Characters from languages are such as Arabic, Hebrew are displayed from RTL (Right To Left) order in Opera 372017-01-26