Representation of DOM attribute values could allow cross-site scripting – Opera Security Advisories

Severity

Moderately Severe

Problem Description

When XML is imported into a document, its attribute values are not correctly presented to the DOM. This can allow their values to bypass sanitization filters. If these values are used as document content, they may in some cases allow scripts to be inserted.

Opera’s Response

Opera Software has released Opera 9.26, where this issue has been fixed.

Credits

Thanks to Arnaud Le Blanc for reporting this issue to Opera Software.