CVE-2023-25731
Last modified
CVE-2023-25731 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Due to URL previews in the network panel of developer tools improperly storing URLs, query parameters could potentially be used to overwrite global objects in privileged code. This vulnerability affects Firefox < 110.. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
Due to URL previews in the network panel of developer tools improperly storing URLs, query parameters could potentially be used to overwrite global objects in privileged code. This vulnerability affects Firefox < 110.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 110.0 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1801542Issue Tracking, Permissions Required
- https://www.mozilla.org/security/advisories/mfsa2023-05/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1801542Issue Tracking, Permissions Required
- https://www.mozilla.org/security/advisories/mfsa2023-05/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1801542Issue Tracking, Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-25731?
How severe is CVE-2023-25731?
How do I fix CVE-2023-25731?
Are you affected by CVE-2023-25731?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
