Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q432-46p9-q7g4

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A "javascript:" url loaded by a malicious page can obfuscate its location by blanking the URL displayed in the addressbar, allowing for an attacker to spoof an existing page without the malicious page's address being displayed correctly. This vulnerability affects Firefox < 52.

A "javascript:" url loaded by a malicious page can obfuscate its location by blanking the URL displayed in the addressbar, allowing for an attacker to spoof an existing page without the malicious page's address being displayed correctly. This vulnerability affects Firefox < 52.

EPSS

Процентиль: 68%
0.01277
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 8 лет назад

A "javascript:" url loaded by a malicious page can obfuscate its location by blanking the URL displayed in the addressbar, allowing for an attacker to spoof an existing page without the malicious page's address being displayed correctly. This vulnerability affects Firefox < 52.

CVSS3: 6.5
nvd
около 8 лет назад

A "javascript:" url loaded by a malicious page can obfuscate its location by blanking the URL displayed in the addressbar, allowing for an attacker to spoof an existing page without the malicious page's address being displayed correctly. This vulnerability affects Firefox < 52.

CVSS3: 6.5
debian
около 8 лет назад

A "javascript:" url loaded by a malicious page can obfuscate its locat ...

suse-cvrf
больше 9 лет назад

Security update for MozillaFirefox, mozilla-nss

EPSS

Процентиль: 68%
0.01277
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-20