Security Advisory

CVE-2016-9901

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-06-11 21:00:00
Last updated 2024-08-06 03:07:31
Assigner mozilla
CVSS score not scored
State PUBLISHED

Description

HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will be run in the "about:pocket-saved" (unprivileged) page, giving it access to Pocket's messaging API through HTML injection. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.