Security Advisory

CVE-2019-11695

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-07-23 13:22:31
Last updated 2024-08-04 23:03:32
Assigner mozilla
CVSS score not scored
State PUBLISHED

Description

A custom cursor defined by scripting on a site can position itself over the addressbar to spoof the actual cursor when it should not be allowed outside of the primary web content area. This could be used by a malicious site to trick users into clicking on permission prompts, doorhanger notifications, or other buttons inadvertently if the location is spoofed over the user interface. This vulnerability affects Firefox < 67.