CVE-2016-9903: XSS
Published Dec 13, 2016
·Updated
Mozilla's add-ons SDK had a world-accessible resource with an HTML injection vulnerability. If an additional vulnerability allowed this resource to be loaded as a document it could allow injecting content and script into an add-on's context.
Affected Software
2 affected componentsFixes available
Mozilla Firefox<50.1
50.1
Mozilla Firefox<50.1
Remediation
Patch Available
Event History
Dec 13, 2016
CVE Published
12:00 AM
Jun 11, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2016-9903?
CVE-2016-9903 is classified as a medium-severity vulnerability.
2
How do I fix CVE-2016-9903?
To fix CVE-2016-9903, update Mozilla Firefox to version 50.1 or later.
3
What type of vulnerability is CVE-2016-9903?
CVE-2016-9903 is an HTML injection vulnerability affecting Mozilla's add-ons SDK.
4
Which versions of Firefox are affected by CVE-2016-9903?
Firefox versions prior to 50.1 are affected by CVE-2016-9903.
5
Can CVE-2016-9903 allow unauthorized content injection?
Yes, CVE-2016-9903 can potentially allow malicious content and script injection into an add-on's context.