cve/2024/CVE-2024-0747.md
2024-05-25 21:48:12 +02:00

1.1 KiB

CVE-2024-0747

Description

When a parent page loaded a child in an iframe with unsafe-inline, the parent Content Security Policy could have overridden the child Content Security Policy. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

POC

Reference

No PoCs from references.

Github