diff --git a/cves/CVE-2011-3058.yml b/cves/CVE-2011-3058.yml index dc6327b67..d216f2864 100644 --- a/cves/CVE-2011-3058.yml +++ b/cves/CVE-2011-3058.yml @@ -32,7 +32,9 @@ description_instructions: | that outsiders to Chromium would not understand. Technology like "regular expressions" is fine, and security phrases like "invalid write" are fine to keep too. -description: +description: This Cross-Site Scripting (XSS) vulnerability is caused by an improper handling + of the EUC-JP encoding system, making it difficult for website owners to validate user input. + This might have allowed remote attackers to execute XSS attacks. bounty_instructions: | If you came across any indications that a bounty was paid out for this vulnerability, fill it out here. Or correct it if the information already here @@ -60,7 +62,7 @@ upvotes_instructions: | upvotes to each vulnerability you see. Your peers will tell you how interesting they think this vulnerability is, and you'll add that to the upvotes score on your branch. -upvotes: +upvotes: 10 unit_tested: question: | Were automated unit tests involved in this vulnerability?