First published: Thu Sep 24 2015(Updated: )
Mozilla Firefox before 41.0, when reader mode is enabled, allows remote attackers to spoof the relationship between address-bar URLs and web content via a crafted web site.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <=40.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4508 has been classified as a medium severity vulnerability due to its potential to allow URL spoofing.
To fix CVE-2015-4508, upgrade Mozilla Firefox to version 41.0 or later.
CVE-2015-4508 can be exploited by remote attackers to spoof the relationship between the address bar URLs and the content displayed in reader mode.
CVE-2015-4508 affects Mozilla Firefox versions before 41.0.
CVE-2015-4508 allows attackers to create crafted websites that mislead users about the actual URL they are visiting.