Lucene search

K
cvelistMozillaCVELIST:CVE-2022-31743
HistoryDec 22, 2022 - 12:00 a.m.

CVE-2022-31743

2022-12-2200:00:00
mozilla
www.cve.org
7
firefox
html parser
vulnerability
user-controlled data

AI Score

7.4

Confidence

High

EPSS

0.001

Percentile

34.6%

Firefox’s HTML parser did not correctly interpret HTML comment tags, resulting in an incongruity with other browsers. This could have been used to escape HTML comments on pages that put user-controlled data in them. This vulnerability affects Firefox < 101.

CNA Affected

[
  {
    "vendor": "Mozilla",
    "product": "Firefox",
    "versions": [
      {
        "version": "unspecified",
        "lessThan": "101",
        "status": "affected",
        "versionType": "custom"
      }
    ]
  }
]

AI Score

7.4

Confidence

High

EPSS

0.001

Percentile

34.6%