Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36927
HistorySep 04, 2022 - 11:42 a.m.

Arbitrary Code Execution

2022-09-0411:42:34
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
arbitrary code execution
firefox-esr
cross-origin iframe
xslt document
parent domain permissions
software

0.003 Low

EPSS

Percentile

65.6%

firefox-esr is vulnerable to arbitrary code execution. The vulnerability is possible because the cross-origin iframe referencing an XSLT document inheriting the parent domain’s permissions which allows an attacker to inject and execute arbitrary commands.