Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9f9w-vwq3-c9fh

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

The Firefox Health Reports (aka FHR or about:healthreport) feature in Mozilla Firefox before 46.0 does not properly restrict the origin of events, which makes it easier for remote attackers to modify sharing preferences by leveraging access to the remote-report IFRAME element.

The Firefox Health Reports (aka FHR or about:healthreport) feature in Mozilla Firefox before 46.0 does not properly restrict the origin of events, which makes it easier for remote attackers to modify sharing preferences by leveraging access to the remote-report IFRAME element.

EPSS

Процентиль: 61%
0.00421
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 10 лет назад

The Firefox Health Reports (aka FHR or about:healthreport) feature in Mozilla Firefox before 46.0 does not properly restrict the origin of events, which makes it easier for remote attackers to modify sharing preferences by leveraging access to the remote-report IFRAME element.

redhat
почти 10 лет назад

The Firefox Health Reports (aka FHR or about:healthreport) feature in Mozilla Firefox before 46.0 does not properly restrict the origin of events, which makes it easier for remote attackers to modify sharing preferences by leveraging access to the remote-report IFRAME element.

CVSS3: 4.3
nvd
почти 10 лет назад

The Firefox Health Reports (aka FHR or about:healthreport) feature in Mozilla Firefox before 46.0 does not properly restrict the origin of events, which makes it easier for remote attackers to modify sharing preferences by leveraging access to the remote-report IFRAME element.

CVSS3: 4.3
debian
почти 10 лет назад

The Firefox Health Reports (aka FHR or about:healthreport) feature in ...

fstec
почти 10 лет назад

Уязвимость браузера Firefox, позволяющая нарушителю внести изменения в настройки общего доступа

EPSS

Процентиль: 61%
0.00421
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-284