CVE-2023-25731
Last modified
CVE-2023-25731 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Due to URL previews in the network panel of developer tools improperly storing URLs, query parameters could potentially be used to overwrite global objects in privileged code. This vulnerability affects Firefox < 110.. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
Due to URL previews in the network panel of developer tools improperly storing URLs, query parameters could potentially be used to overwrite global objects in privileged code. This vulnerability affects Firefox < 110.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 110.0 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1801542Issue Tracking, Permissions Required
- https://www.mozilla.org/security/advisories/mfsa2023-05/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1801542Issue Tracking, Permissions Required
- https://www.mozilla.org/security/advisories/mfsa2023-05/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1801542Issue Tracking, Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-25731?
How severe is CVE-2023-25731?
How do I fix CVE-2023-25731?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-25725HAProxy before 2.7.3 may allow a bypass of access control be…9.1
- CVE-2023-25727In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authent…5.4
- CVE-2023-25728The <code>Content-Security-Policy-Report-Only</code> header …6.5
- CVE-2023-25729Permission prompts for opening external schemes were only sh…8.8
- CVE-2023-2573Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 …8.8
- CVE-2023-25730A background script invoking <code>requestFullscreen</code> …5.4
- CVE-2023-25732When encoding data from an <code>inputStream</code> in <code…8.8
- CVE-2023-25733The return value from `gfx::SourceSurfaceSkia::Map()` wasn't…7.5
- CVE-2023-25734After downloading a Windows <code>.url</code> shortcut from …8.1
- CVE-2023-25735Cross-compartment wrappers wrapping a scripted proxy could h…8.8
- CVE-2023-25736An invalid downcast from `nsHTMLDocument` to `nsIContent` co…9.8
- CVE-2023-25737An invalid downcast from <code>nsTextNode</code> to <code>SV…8.8
Are you affected by CVE-2023-25731?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
