CVE-2022-22755

CVSS v3.1 8.8 (High)
88% Progress
EPSS 0.19 % (56th)
0.19% Progress
Affected Products 1
Advisories 4

By using XSL Transforms, a malicious webserver could have served a user an XSL document that would continue to execute JavaScript (within the bounds of the same-origin policy) even after the tab was closed. This vulnerability affects Firefox < 97.

Weaknesses
CWE-672
Operation on a Resource after Expiration or Release
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2022-12-22 20:15:18
(21 months ago)
Updated Date
2022-12-29 23:08:47
(20 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox prior 97.0 version cpe:2.3:a:mozilla:firefox < 97.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...