PT-2015-2626 · Mozilla+3 · Firefox+3
Jason Hamilton
+3
·
Published
2015-11-03
·
Updated
2024-12-12
·
CVE-2015-7187
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox versions prior to 42.0
Description
The issue is related to errors in security settings within the Add-on SDK of Mozilla Firefox. It allows a remote attacker to conduct cross-site scripting (XSS) attacks using specially crafted JavaScript code. The vulnerability arises from the misinterpretation of a "script: false" panel setting, making it easier for attackers to execute inline JavaScript code within third-party extensions.
Recommendations
For versions prior to 42.0, update to version 42.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of third-party extensions until the update is applied.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Firefox
Suse
Ubuntu