Search the knowledge base

Advisory: Script injection in feed preview can reveal contents of unrelated news feeds

Severity

Highly Severe

Problem Description

When Opera is previewing a news feed, some scripted URLs are not correctly blocked. These can execute scripts which are able to subscribe the user to any feed URL that the attacker chooses, and can also view the contents of any feeds that the user is subscribed to. These may contain sensitive information.

Opera's Response

Opera Software has released Opera 9.63, where this issue has been fixed.

Credits

Thanks to David Bloom for reporting this issue to Opera Software.


Browse through articles in the same categories: advisory

Support

Opera Help

Need help? Hit F1 anytime while using Opera to access our online help files, or go here.