cve/2015/CVE-2015-7187.md
2024-06-18 02:51:15 +02:00

756 B

CVE-2015-7187

Description

The Add-on SDK in Mozilla Firefox before 42.0 misinterprets a "script: false" panel setting, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via inline JavaScript code that is executed within a third-party extension.

POC

Reference

Github

No PoCs found on GitHub currently.