PT-2018-8246 · Mozilla+2 · Firefox For Android+2
Jordi Chancel
·
Publicado
2017-02-02
·
Atualizado
2024-12-12
·
CVE-2017-5394
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Firefox for Android versions prior to 51
Description:
The issue is a location bar spoofing attack that occurs when a series of JavaScript events are combined with fullscreen mode, causing the location bar of a loaded page to be shown over the content of another tab. This problem is specific to Firefox for Android and does not affect other operating systems.
Recommendations:
For Firefox for Android versions prior to 51, update to version 51 or later to resolve the issue.
Exploit
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Firefox For Android
Suse