PT-2015-1847 · Mozilla · Firefox Os

Muneaki Nishimura

·

Published

2015-08-06

·

Updated

2015-08-10

·

CVE-2015-2744

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Mozilla Firefox OS versions prior to 2.2
Description The issue is related to a cross-site scripting (XSS) vulnerability in the Search app component of Gaia in Mozilla Firefox OS. This vulnerability allows remote attackers to inject arbitrary HTML code via a crafted search link that is mishandled after re-opening the browser or opening the tab view. The exploitation of this vulnerability can enable a remote attacker to inject arbitrary HTML code using a special search query executed after restarting the browser or opening a new tab.
Recommendations For versions prior to 2.2, update to version 2.2 or later to resolve the issue.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-11193
CVE-2015-2744

Affected Products

Firefox Os