Files
CVEs-PoC/2015/CVE-2015-7187.md
2025-09-29 21:09:30 +02:00

767 B

CVE-2015-7187

Description

The Add-on SDK in Mozilla Firefox before 42.0 misinterprets a "script: false" panel setting, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via inline JavaScript code that is executed within a third-party extension.

POC

Reference

Github

No PoCs found on GitHub currently.