4.3
CVSSv2

CVE-2015-7187

Published: 05/11/2015 Updated: 07/12/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The Add-on SDK in Mozilla Firefox prior to 42.0 misinterprets a "script: false" panel setting, which makes it easier for remote malicious users to conduct cross-site scripting (XSS) attacks via inline JavaScript code that is executed within a third-party extension.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

Vendor Advisories

Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2015-121 Disabling scripts in Add-on SDK panels has no effect Announced November 3, 2015 Reporter Jason Hamilton, Peter Arremann, Sylvain Giroux Impact Moderate Products Firefox Fix ...
The Add-on SDK in Mozilla Firefox before 420 misinterprets a "script: false" panel setting, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via inline JavaScript code that is executed within a third-party extension ...