Saturday, February 12, 2022

MFSA2022-05 Firefox: Security Vulnerabilities fixed in Firefox ESR 91.6 (CVE-2022-22759)

Description
If a document created a sandboxed iframe without allow-scripts, and subsequently appended an element to the iframe's document that e.g. had a JavaScript event handler - the event handler would have run despite the iframe's sandbox.
Solution(s)
  • mozilla-firefox-esr-upgrade-91_6


  • References
  • https://attackerkb.com/topics/cve-2022-22759
  • CVE - 2022-22759
  • http://www.mozilla.org/security/announce/2022/mfsa2022-05.html




  •  

    Copyright © 2021 Vulnerability Database | Cyber Details™

    thank you Templateism for the design - You should have written the code a little more complicated - Nothing Encrypted anymore