CVE-2016-2820

CVSS v3.0 4.3 (Medium)
43% Progress
CVSS v2.0 4.3 (Medium)
43% Progress
EPSS 0.91 % (83th)
0.91% Progress
Affected Products 1
Advisories 3

The Firefox Health Reports (aka FHR or about:healthreport) feature in Mozilla Firefox before 46.0 does not properly restrict the origin of events, which makes it easier for remote attackers to modify sharing preferences by leveraging access to the remote-report IFRAME element.

Weaknesses
CWE-284
Improper Access Control
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2016-04-30 17:59:15
(8 years ago)
Updated Date
2017-07-01 01:29:40
(7 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox 45.0.2 and prior versions cpe:2.3:a:mozilla:firefox <= 45.0.2
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...