Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q432-46p9-q7g4

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A "javascript:" url loaded by a malicious page can obfuscate its location by blanking the URL displayed in the addressbar, allowing for an attacker to spoof an existing page without the malicious page's address being displayed correctly. This vulnerability affects Firefox < 52.

A "javascript:" url loaded by a malicious page can obfuscate its location by blanking the URL displayed in the addressbar, allowing for an attacker to spoof an existing page without the malicious page's address being displayed correctly. This vulnerability affects Firefox < 52.

EPSS

Процентиль: 60%
0.00398
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

A "javascript:" url loaded by a malicious page can obfuscate its location by blanking the URL displayed in the addressbar, allowing for an attacker to spoof an existing page without the malicious page's address being displayed correctly. This vulnerability affects Firefox < 52.

CVSS3: 6.5
nvd
больше 7 лет назад

A "javascript:" url loaded by a malicious page can obfuscate its location by blanking the URL displayed in the addressbar, allowing for an attacker to spoof an existing page without the malicious page's address being displayed correctly. This vulnerability affects Firefox < 52.

CVSS3: 6.5
debian
больше 7 лет назад

A "javascript:" url loaded by a malicious page can obfuscate its locat ...

suse-cvrf
почти 9 лет назад

Security update for MozillaFirefox, mozilla-nss

EPSS

Процентиль: 60%
0.00398
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-20