PT-2024-25034 · Unknown · Pwasforfirefox

Filips123

·

Published

2024-05-03

·

Updated

2024-05-03

·

CVE-2024-32986

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PWAsForFirefox versions prior to 2.12.0
Description The issue arises from improper sanitization of web app properties, such as name, description, and shortcuts, allowing malicious web apps to inject additional lines into XDG Desktop Entries on Linux and AppInfo.ini on PortableApps.com. This enables malicious web apps to introduce keys like Exec, which can run arbitrary code when the affected web app is launched. The vulnerability affects Linux and PortableApps.com users. There are no known workarounds for this issue.
Recommendations For PWAsForFirefox versions prior to 2.12.0, update to version 2.12.0 as soon as possible to fix the vulnerability. It is also recommended for Windows and macOS users to update to this version, as it contains additional fixes related to properties sanitization.

Exploit

Fix

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2024-32986
GHSA-JMHV-M7V5-G5JQ

Affected Products

Pwasforfirefox