cve/2024/CVE-2024-10461.md
2025-09-29 21:09:30 +02:00

1.0 KiB

CVE-2024-10461

Description

In multipart/x-mixed-replace responses, Content-Disposition: attachment in the response header was not respected and did not force a download, which could allow XSS attacks. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

POC

Reference

Github

No PoCs found on GitHub currently.