PT-2015-2626 · Mozilla+3 · Firefox+3
Jason Hamilton
+3
·
Publicado
2015-11-03
·
Atualizado
2024-12-12
·
CVE-2015-7187
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox versions prior to 42.0
Description
The issue is related to errors in security settings within the Add-on SDK of Mozilla Firefox. It allows a remote attacker to conduct cross-site scripting (XSS) attacks using specially crafted JavaScript code. The vulnerability arises from the misinterpretation of a "script: false" panel setting, making it easier for attackers to execute inline JavaScript code within third-party extensions.
Recommendations
For versions prior to 42.0, update to version 42.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of third-party extensions until the update is applied.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Firefox
Suse
Ubuntu