Sites can change framed content on other sites – Opera Security Advisories


Highly Severe

Problem Description

Scripts are able to change the addresses of framed pages that come from the same site. Due to a flaw in the way that Opera checks what frames can be changed, a site can change the address of frames on other sites inside any window that it has opened. This allows sites to open pages from other sites, and display misleading information on them.


Opera’s Response

Opera Software has released Opera 9.52, where this issue has been fixed.