Collected research
Local File Read via Stored XSS in The Opera Browser
Bug Bounty Guest Post: Local File Read via Stored XSS in The Opera Browser
Opera Pinboards accepted a javascript URI as a saved pin, which then ran inside the privileged opera scheme when the link was middle-clicked. From there the researcher called native APIs to open a local file in a tab and capture its thumbnail, exfiltrating a screenshot of that file to a remote server.
Record
- Document
- Bug Bounty Guest Post: Local File Read via Stored XSS in The Opera Browser
- Researcher
- Renwa
- Published by
- Opera Security
- Date
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Renwa, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .