cve/2019/CVE-2019-17001.md
2024-06-09 00:33:16 +00:00

944 B

CVE-2019-17001

Description

A Content-Security-Policy that blocks in-line scripts could be bypassed using an object tag to execute JavaScript in the protected document (cross-site scripting). This is a separate bypass from CVE-2019-17000.Note: This flaw only affected Firefox 69 and was not present in earlier versions.. This vulnerability affects Firefox < 70.

POC

Reference

Github

No PoCs found on GitHub currently.