Beveiligingsadvies

CVE-2019-11718

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2019-07-23 13:17:58
Laatst bijgewerkt 2024-08-04 23:03:32
Toegewezen door mozilla
CVSS-score geen score
Status PUBLISHED

Beschrijving

Activity Stream can display content from sent from the Snippet Service website. This content is written to innerHTML on the Activity Stream page without sanitization, allowing for a potential access to other information available to the Activity Stream, such as browsing history, if the Snipper Service were compromised. This vulnerability affects Firefox < 68.