Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-34477
HistoryDec 22, 2022 - 8:15 p.m.

Cross site scripting

2022-12-2220:15:00
PRIOn knowledge base
www.prio-n.com
3
cross site scripting
information leakage
same-site
cross-origin
xs-leaks attacks
vulnerability
firefox 102

6.9 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

51.7%

The MediaError message property should be consistent to avoid leaking information about cross-origin resources; however for a same-site cross-origin resource, the message could have leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 102.

CPENameOperatorVersion
firefoxlt102.0

6.9 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

51.7%