CVE-2018-12448

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
02/08/2018
Last modified:
09/10/2019

Description

Whale Browser before 1.3.48.4 displays no URL information but only a title of a web page on the browser's address bar when visiting a non-http page, which allows an attacker to display a malicious web page with a fake domain name.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:navercorp:whale:*:*:*:*:*:*:*:* 1.3.48.4 (excluding)


References to Advisories, Solutions, and Tools