Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24006
HistoryApr 10, 2020 - 12:43 a.m.

Cross-site Scripting (XSS)

2020-04-1000:43:47
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
33

EPSS

0.004

Percentile

73.4%

Mozilla Firefox is vulnerable to cross-site scripting (XSS). It happens due to the way Firefox handled the “Content-Disposition: attachment” HTTP header when the “Content-Type: multipart” HTTP header was also present. A website that allows arbitrary uploads and relies on the “Content-Disposition: attachment” HTTP header to prevent content from being displayed inline, could be used by an attacker to serve malicious content to users.

References