Уязвимость внедрения HTML кода в браузере Firefox через неподготовленные HTML теги при обработке сервера Pocket
Описание
Данная уязвимость связана с тем, что HTML теги, полученные от сервера Pocket, обрабатываются без специальной фильтрации. В результате этого JavaScript код может быть выполнен на странице "about:pocket-saved", что предоставляет доступ к API обмена сообщениями Pocket через HTML внедрение.
Затронутые версии ПО
- Firefox ESR версий ниже 45.6
- Firefox версий ниже 50.1
Тип уязвимости
HTML внедрение
Ссылки
- Third Party Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Issue TrackingPatch
- Third Party Advisory
- Vendor Advisory
- Vendor Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Issue TrackingPatch
- Third Party Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Одно из
Одно из
EPSS
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
Связанные уязвимости
HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will be run in the "about:pocket-saved" (unprivileged) page, giving it access to Pocket's messaging API through HTML injection. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.
HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will be run in the "about:pocket-saved" (unprivileged) page, giving it access to Pocket's messaging API through HTML injection. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.
HTML tags received from the Pocket server will be processed without sa ...
HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will be run in the "about:pocket-saved" (unprivileged) page, giving it access to Pocket's messaging API through HTML injection. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.
EPSS
9.8 Critical
CVSS3
7.5 High
CVSS2