ZeroHour

CVE-2019-11724

PoC
CVSS 3.1
6.1 medium
EPSS
1%p64
Published
()
Modified
Description

Application permissions give additional remote troubleshooting permission to the site input.mozilla.org, which has been retired and now redirects to another site. This additional permission is unnecessary and is a potential vector for malicious attacks. This vulnerability affects Firefox < 68.

Vendors
mozillaopensuse
Products
firefox, leap
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.