Opera before 9.52 does not ensure that the address field of a news feed represents the feed's actual URL, which allows remote attackers to change this field to display the URL of a page containing web script controlled by the attacker.
Get an AI-powered plain-language explanation of this vulnerability and remediation steps.
Login to generate AI explanation32 reference(s) from NVD