[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195521

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

URL Spoofing via javascript - CVE-2020-6808

ID: oval:org.secpod.oval:def:61958Date: (C)2020-03-12   (M)2023-11-19
Class: VULNERABILITYFamily: macos




Mozilla Firefox 74 : When a JavaScript URL (javascript:) is evaluated and the result is a string, this string is parsed to create an HTML document, which is then presented. Previously, this document's URL (as reported by the document.location property, for example) was the originating javascript: URL which could lead to spoofing attacks; it is now correctly the URL of the originating document.

Platform:
Apple Mac OS 14
Apple Mac OS 13
Apple Mac OS 12
Apple Mac OS 11
Apple Mac OS X 10.11
Apple Mac OS X 10.12
Apple Mac OS X 10.13
Apple Mac OS X 10.14
Apple Mac OS X 10.15
Product:
Mozilla Firefox
Reference:
CVE-2020-6808
CVE    1
CVE-2020-6808

© SecPod Technologies