PT-2015-2622 · Mozilla+1 · Firefox+1

Muneaki Nishimura

·

Published

2015-11-05

·

Updated

2024-12-12

·

CVE-2015-7191

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 42.0 on Android
Description The issue exists due to improper restriction of URL strings, allowing a remote attacker to conduct cross-site scripting (XSS) attacks. This can be achieved through vectors involving an intent: URL and fallback navigation.
Recommendations For Mozilla Firefox versions prior to 42.0 on Android, update to version 42.0 or later to resolve the issue.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-11987
CVE-2015-7191
OPENSUSE-SU-2015_1942-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:14572-1

Affected Products

Firefox
Suse