Permissions, privileges, and access controls in Microsoft Edge and Microsoft Internet Explorer - CVE-2019-1192
Published: August 14, 2019
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to incorrect processing of requests with different origins. A remote attacker can create a specially crafted webpage, trick the victim into opening it, bypass implemented Same-Origin Policy (SOP) restrictions and gain access to information, related to another domain.
Affected software
Microsoft Internet Explorer