PT-2014-7206 · Facebook · Facebook App+1

William Costa

·

Publicado

2014-09-15

·

Atualizado

2024-08-06

·

CVE-2014-6392

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Facebook app version 14.0 Facebook Messenger app version 10.0
Description A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via a crafted filename extension that is improperly handled during MIME sniffing of chat traffic. The vendor disputes the significance of this report, citing that the user must accept an interstitial warning before the HTML file content is rendered, and the HTML content's origin is a sandbox domain.
Recommendations For Facebook app version 14.0, consider disabling the rendering of HTML file content from chat traffic until a patch is available. For Facebook Messenger app version 10.0, restrict the handling of crafted filename extensions to minimize the risk of exploitation.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-6392

Produtos afetados

Facebook Messenger
Facebook App