PT-2015-1848 · Mozilla · Firefox Os
Muneaki Nishimura
·
Publicado
2015-08-06
·
Atualizado
2015-08-10
·
CVE-2015-2745
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox OS versions prior to 2.2
Description
The issue allows remote attackers to inject arbitrary HTML via the
name or title field in card content associated with a search link that is mishandled after a HOME button press or a Show Windows action. This can be demonstrated by embedding an arbitrary application or spoofing the account-creation page. The vulnerability exists due to the lack of protection of the web page structure in the Gaia Search app component of the Firefox OS.Recommendations
For versions prior to 2.2, update to version 2.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of the Search app in Gaia until a patch is available. Avoid using the
name and title fields in the search link card content to minimize the risk of exploitation.Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Firefox Os