CVE-2015-7223Cross-site Scripting in Mozilla Firefox

CWE-2647 documents6 sources
Severity
4.0MEDIUMNVD
OSV10.0
EPSS
0.7%
top 26.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 16
Latest updateMay 14

Description

The WebExtension APIs in Mozilla Firefox before 43.0 allow remote attackers to gain privileges, and possibly obtain sensitive information or conduct cross-site scripting (XSS) attacks, via a crafted web site.

CVSS vector

AV:N/AC:H/C:P/I:P/A:NExploitability: 4.9 | Impact: 4.9

Affected Packages4 packages

Ubuntumozilla/firefox< 43.0+build1-0ubuntu0.14.04.1
NVDmozilla/firefox42.0
NVDopensuse/leap42.1
NVDopensuse/opensuse13.1, 13.2+1

Also affects: Fedora 22, 23

🔴Vulnerability Details

3
GHSA
GHSA-q5v7-p6px-6x4f: The WebExtension APIs in Mozilla Firefox before 432022-05-14
OSV
firefox vulnerabilities2015-12-15
OSV
CVE-2015-7223: The WebExtension APIs in Mozilla Firefox before 432015-12-15

📋Vendor Advisories

2
Red Hat
Mozilla: Privilege escalation vulnerabilities in WebExtension APIs (MFSA 2015-148)2015-12-16
Ubuntu
Firefox vulnerabilities2015-12-15

💬Community

1
Bugzilla
CVE-2015-7223 Mozilla: Privilege escalation vulnerabilities in WebExtension APIs (MFSA 2015-148)2015-12-15
CVE-2015-7223 — Cross-site Scripting in Mozilla Firefox | cvebase