Data URIs can be used to allow cross-site scripting – Opera Security Advisories

Severity

Highly severe

Description

Data URIs are allowed to run scripts that manipulate pages from the site that directly opened them. In some cases, the opening site is not correctly detected. In these cases, Data URIs may erroneously be able to run scripts so that they interact with sites that did not directly cause them to be opened.

Opera’s response

Opera Software has released Opera 10.54 on Windows and Mac, and Opera 10.11 on Linux and FreeBSD, where this issue has been fixed.