#VU9285 Open redirect in Microsoft Edge - CVE-2017-11872
Published: November 14, 2017
Microsoft Edge
Microsoft
Description
The vulnerability exists due to improper handling of redirect requests by Microsoft Edge. A remote attacker can bypass Cross-Origin Resource Sharing (CORS) redirect restrictions, trick the victim into visiting a specially crafted website and force the browser to send data that would otherwise be restricted to a destination website of the attacker's choice.