CVE-2016-2820 — Improper Access Control in Firefox
Severity
4.3MEDIUMNVD
OSV8.8
EPSS
0.4%
top 37.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 30
Latest updateMay 17
Description
The Firefox Health Reports (aka FHR or about:healthreport) feature in Mozilla Firefox before 46.0 does not properly restrict the origin of events, which makes it easier for remote attackers to modify sharing preferences by leveraging access to the remote-report IFRAME element.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4
Affected Packages4 packages
🔴Vulnerability Details
4📋Vendor Advisories
5💬Community
1Bugzilla▶
CVE-2016-2820 Mozilla: Firefox Health Reports could accept events from untrusted domains (MFSA 2016-48)↗2016-04-25