Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-46873
HistoryDec 22, 2022 - 8:15 p.m.

Code injection

2022-12-2220:15:00
PRIOn knowledge base
www.prio-n.com
4
firefox
code injection
content security policy
vulnerability
executable script

8 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

61.2%

Because Firefox did not implement the <code>unsafe-hashes</code> CSP directive, an attacker who was able to inject markup into a page otherwise protected by a Content Security Policy may have been able to inject executable script. This would be severely constrained by the specified Content Security Policy of the document. This vulnerability affects Firefox < 108.

CPENameOperatorVersion
firefoxlt108.0

8 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

61.2%