First published: Sat Aug 08 2015(Updated: )
Cross-site scripting (XSS) vulnerability in the Search app in Gaia in Mozilla Firefox OS before 2.2 allows remote attackers to inject arbitrary HTML via a crafted search link that is mishandled after re-opening the browser or opening the tab view.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox OS | <=2.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2744 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
To mitigate CVE-2015-2744, upgrade to Mozilla Firefox OS version 2.2 or later.
CVE-2015-2744 can enable remote attackers to inject arbitrary HTML into the web page via a crafted search link.
CVE-2015-2744 affects versions of Mozilla Firefox OS prior to 2.2, including all versions up to 2.1.0.
Users affected by CVE-2015-2744 may be exposed to malicious scripts that can manipulate or steal information from the browser.