CVE-2015-2744: XSS
Cross-site scripting (XSS) vulnerability in the Search app in Gaia in Mozilla Firefox OS before 2.2 allows remote attackers to inject arbitrary HTML via a crafted search link that is mishandled after re-opening the browser or opening the tab view.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2744?
CVE-2015-2744 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2015-2744?
To mitigate CVE-2015-2744, upgrade to Mozilla Firefox OS version 2.2 or later.
What types of attacks can CVE-2015-2744 enable?
CVE-2015-2744 can enable remote attackers to inject arbitrary HTML into the web page via a crafted search link.
Which versions of Mozilla Firefox OS are affected by CVE-2015-2744?
CVE-2015-2744 affects versions of Mozilla Firefox OS prior to 2.2, including all versions up to 2.1.0.
What impact does CVE-2015-2744 have on users?
Users affected by CVE-2015-2744 may be exposed to malicious scripts that can manipulate or steal information from the browser.