CVE-2010-3020 describes a vulnerability in Opera versions prior to 10.61, where the news-feed preview feature fails to adequately remove scripts. This flaw allows remote attackers to force users into subscribing to arbitrary news feeds through specially crafted content. With a CVSS score of 5.0 (AV:N/AC:L/Au:N/C:N/I:P/A:N), it is a medium-severity vulnerability that requires no authentication and has a low attack complexity, primarily impacting integrity. There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage, indicating it is not a widely targeted or discussed threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.60CPE matchmatch criteria | cpe:2.3:a:opera:opera_browser:*:*:*:*:*:*:*:* | ||
1.00CPE matchmatch criteria | cpe:2.3:a:opera:opera_browser:1.00:*:*:*:*:*:*:* | ||
2.00CPE matchmatch criteria | cpe:2.3:a:opera:opera_browser:2.00:*:*:*:*:*:*:* | ||
2.10CPE matchmatch criteria | cpe:2.3:a:opera:opera_browser:2.10:*:*:*:*:*:*:* | ||
2.10CPE matchmatch criteria | cpe:2.3:a:opera:opera_browser:2.10:beta1:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.