CVE-2022-31743 — Cross-site Scripting in Mozilla Firefox
Severity
6.5MEDIUMNVD
EPSS
0.6%
top 30.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 22
Description
Firefox's HTML parser did not correctly interpret HTML comment tags, resulting in an incongruity with other browsers. This could have been used to escape HTML comments on pages that put user-controlled data in them. This vulnerability affects Firefox < 101.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6
Affected Packages5 packages
🔴Vulnerability Details
2GHSA▶
GHSA-6wvv-23hx-p89r: Firefox's HTML parser did not correctly interpret HTML comment tags, resulting in an incongruity with other browsers↗2022-12-22
OSV▶
CVE-2022-31743: Firefox's HTML parser did not correctly interpret HTML comment tags, resulting in an incongruity with other browsers↗2022-06-01