Beveiligingsadvies

CVE-2025-3033

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-04-01 12:29:04
Laatst bijgewerkt 2026-04-13 14:29:35
Toegewezen door mozilla
CVSS-score 7.7
Status PUBLISHED

Beschrijving

After selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file could be uploaded. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 137 and Thunderbird 137.