Severity
4.3MEDIUMNVD
OSV8.8
EPSS
0.1%
top 74.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 7
Latest updateDec 24

Description

Inappropriate implementation in Internals in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to spoof the origin of an iframe via a crafted HTML page. (Chromium security severity: Low)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages17 packages

CVEListV5google/chrome111.0.5563.64111.0.5563.64
NVDgoogle/chrome< 111.0.5563.64
debiandebian/chromium< chromium 111.0.5563.64-1 (bookworm)
Debianchromium/chromium< 111.0.5563.64-1~deb11u1+3

🔴Vulnerability Details

11
OSV
iommufd: Set end correctly when doing batch carry2025-12-24
GHSA
phpMyFAQ contains a CSV injection vulnerability2025-12-18
GHSA
ActiveAdmin CSV Injection leading to sensitive information disclosure2023-12-28
GHSA
Potential CSV export data leak2023-12-15
GHSA
phpMyFAQ Improper Neutralization of Formula Elements in a CSV File vulnerability2023-07-31

📋Vendor Advisories

6
Fortinet
A improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, 7.0...2024-03-12
Microsoft
Chromium: CVE-2023-1236 Inappropriate implementation in Internals2023-03-14
Ubuntu
Chromium vulnerabilities2023-03-13
Chrome
Stable Channel Update for Desktop: CVE-2023-12362023-03-07
Fortinet
CSV injection in macro name2023-03-07