Web Hack List

Collected research

Local File Read via Stored XSS in The Opera Browser

Bug Bounty Guest Post: Local File Read via Stored XSS in The Opera Browser

Opera Pinboards accepted a javascript URI as a saved pin, which then ran inside the privileged opera scheme when the link was middle-clicked. From there the researcher called native APIs to open a local file in a tab and capture its thumbnail, exfiltrating a screenshot of that file to a remote server.

Record

Document
Bug Bounty Guest Post: Local File Read via Stored XSS in The Opera Browser
Researcher
Renwa
Published by
Opera Security
Date
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Renwa, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .