cve/2015/CVE-2015-7197.md
2024-06-18 02:51:15 +02:00

866 B

CVE-2015-7197

Description

Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 improperly control the ability of a web worker to create a WebSocket object, which allows remote attackers to bypass intended mixed-content restrictions via crafted JavaScript code.

POC

Reference

Github

No PoCs found on GitHub currently.