Vulnerability Description
Due to URL previews in the network panel of developer tools improperly storing URLs, query parameters could potentially be used to overwrite global objects in privileged code. This vulnerability affects Firefox < 110.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 110.0 |
Related Weaknesses (CWE)
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1801542Issue TrackingPermissions Required
- https://www.mozilla.org/security/advisories/mfsa2023-05/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1801542Issue TrackingPermissions Required
- https://www.mozilla.org/security/advisories/mfsa2023-05/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1801542Issue TrackingPermissions Required
FAQ
What is CVE-2023-25731?
CVE-2023-25731 is a vulnerability with a CVSS score of 8.8 (HIGH). Due to URL previews in the network panel of developer tools improperly storing URLs, query parameters could potentially be used to overwrite global objects in privileged code. This vulnerability affec...
How severe is CVE-2023-25731?
CVE-2023-25731 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-25731?
Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Firefox.