An attacker was able to inject an event handler into a...
High severity
Unreviewed
Published
Mar 22, 2024
to the GitHub Advisory Database
•
Updated Mar 14, 2025
Description
Published by the National Vulnerability Database
Mar 22, 2024
Published to the GitHub Advisory Database
Mar 22, 2024
Last updated
Mar 14, 2025
An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. This vulnerability affects Firefox < 124.0.1 and Firefox ESR < 115.9.1.
References