First published: Tue Jul 04 2023(Updated: )
Uploading files which contain symlinks may have allowed an attacker to trick a user into submitting sensitive data to a malicious website. This vulnerability affects Firefox < 115.
Credit: security@mozilla.org security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/firefox | <115.0-1 | 115.0-1 |
ubuntu/firefox | <115.0+ | 115.0+ |
Mozilla Firefox | <115 | 115 |
Mozilla Firefox | <115.0 | |
debian/firefox | 123.0-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID is CVE-2023-37206.
Firefox versions prior to 115 are affected.
The severity of this vulnerability is medium.
An attacker can trick a user into submitting sensitive data to a malicious website by uploading files containing symlinks.
You can find more information about this vulnerability in the following references: [link1](https://bugzilla.mozilla.org/show_bug.cgi?id=1813299), [link2](https://www.mozilla.org/security/advisories/mfsa2023-22/), [link3](https://launchpad.net/bugs/cve/CVE-2023-37206).