Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-23598
HistoryJun 02, 2023 - 5:15 p.m.

Code injection

2023-06-0217:15:00
PRIOn knowledge base
www.prio-n.com
5
code injection
firefox
gtk
vulnerability
file urls
datatransfer.setdata

6.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.5%

Due to the Firefox GTK wrapper code’s use of text/plain for drag data and GTK treating all text/plain MIMEs containing file URLs as being dragged a website could arbitrarily read a file via a call to <code>DataTransfer.setData</code>. This vulnerability affects Firefox < 109, Thunderbird < 102.7, and Firefox ESR < 102.7.