Medium severity5.3OSV Advisory· Published Jan 11, 2018· Updated Jun 17, 2026
CVE-2017-18016
CVE-2017-18016
Description
Parity Browser 1.6.10 and earlier allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by requesting other websites via the Parity web proxy engine (reusing the current website's token, which is not bound to an origin).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: v1.6.0, v1.6.1, v1.6.10, …
- Range: <=1.6.10
Patches
Vulnerability mechanics
References
4- github.com/paritytech/parity/commit/53609f703e2f1af76441344ac3b72811c726a215nvdPatchThird Party Advisory
- www.openwall.com/lists/oss-security/2018/01/10/1nvdExploitMailing ListThird Party Advisory
- github.com/tintinweb/pub/tree/master/pocs/cve-2017-18016nvdExploitTechnical DescriptionThird Party Advisory
- www.exploit-db.com/exploits/43499/nvdExploitThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.