Lucene search

K
mozillaMozilla FoundationMFSA2013-37
HistoryApr 02, 2013 - 12:00 a.m.

Bypass of tab-modal dialog origin disclosure — Mozilla

2013-04-0200:00:00
Mozilla Foundation
www.mozilla.org
32

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

EPSS

0.01

Percentile

83.6%

Security researcher shutdown reported a method for removing the origin indication on tab-modal dialog boxes in combination with browser navigation. This could allow an attacker’s dialog to overlay a page and show another site’s content. This can be used for phishing by allowing users to enter data into a modal prompt dialog on an attacking, site while appearing to be from the displayed site.

Affected configurations

Vulners
Node
mozillafirefoxRange<20
OR
mozillaseamonkeyRange<2.17

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

EPSS

0.01

Percentile

83.6%