Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-31739
HistoryDec 22, 2022 - 8:15 p.m.

Code injection

2022-12-2220:15:00
PRIOn knowledge base
www.prio-n.com
6
code injection
windows
firefox
security vulnerability

8.3 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

52.6%

When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-influenced paths that used variables such as %HOMEPATH% or %APPDATA%.<br>This bug only affects Firefox for Windows. Other operating systems are unaffected.. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

CPENameOperatorVersion
firefoxlt101
firefox_esrlt91.10
thunderbirdlt91.10

8.3 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

52.6%