Due to URL previews in the network panel of developer tools improperly storing URLs, query parameters could potentially be used to overwrite global objects in privileged code. This vulnerability affects Firefox < 110.
References
Link | Resource |
---|---|
https://bugzilla.mozilla.org/show_bug.cgi?id=1801542 | Issue Tracking Permissions Required |
https://www.mozilla.org/security/advisories/mfsa2023-05/ | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mozilla
Published: 2023-06-02T00:00:00
Updated: 2023-06-02T00:00:00
Reserved: 2023-02-13T00:00:00
Link: CVE-2023-25731
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-06-02T17:15:11.147
Modified: 2023-06-08T15:47:20.800
Link: CVE-2023-25731
JSON object: View
Redhat Information
No data.
CWE