Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-68216
HistoryJun 30, 2022 - 12:00 a.m.

Mozilla Firefox Input Validation Error Vulnerability (CNVD-2023-68216)

2022-06-3000:00:00
China National Vulnerability Database
www.cnvd.org.cn
17
mozilla firefox
input validation
vulnerability
drag-and-drop
image feature
malicious code
file system

EPSS

0.002

Percentile

56.1%

Mozilla Firefox is an open source web browser from the Mozilla Foundation in the United States. The input validation error vulnerability exists in Mozilla Firefox due to a lack of restriction and filtering of extensions in the drag-and-drop image feature. The vulnerability can be exploited to execute malicious code by dragging and dropping a malicious image onto the file system.