Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-25729
HistoryJun 02, 2023 - 5:15 p.m.

Design/Logic Flaw

2023-06-0217:15:00
PRIOn knowledge base
www.prio-n.com
11
design flaw
logic flaw
permission prompts
external schemes
contentprincipals
expandedprincipals
malicious actions
file download
software interaction
vulnerability
firefox
thunderbird
firefox esr
nvd

8 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

54.8%

Permission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> resulting in extensions being able to open them without user interaction via <code>ExpandedPrincipals</code>. This could lead to further malicious actions such as downloading files or interacting with software already installed on the system. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.