CVE-2023-25729
Published: Jun 2, 2023
Modified: Jan 10, 2025
Description
Permission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> resulting in extensions being able to open them without user interaction via <code>ExpandedPrincipals</code>. This could lead to further malicious actions such as downloading files or interacting with software already installed on the system. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
| Vendor | Product | Versions |
|---|---|---|
Mozilla | Firefox | affected unspecified - < 110 |
Mozilla | Thunderbird | affected unspecified - < 102.8 |
Mozilla | Firefox ESR | affected unspecified - < 102.8 |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now