Vulnerabilities > CVE-2017-20041 - Improper Restriction of Rendered UI Layers or Frames vulnerability in Ucweb UC Browser 11.2.5.932

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
ucweb
CWE-1021

Summary

A vulnerability was found in Ucweb UC Browser 11.2.5.932. It has been classified as critical. Affected is an unknown function of the component HTML Handler. The manipulation of the argument title leads to improper restriction of rendered ui layers (URL). It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

Vulnerable Configurations

Part Description Count
Application
Ucweb
1