Mozilla Firefox 33.0 and SeaMonkey prior to 2.31 include path strings in CSP violation reports, which allows remote malicious users to obtain sensitive information via a web site that receives a report after a redirect.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
mozilla seamonkey |
||
mozilla firefox 33.0 |