CVE Published: 11/06/2018 |
CVE Updated: 06/08/2024 |
CVE Year: 2016 Source: mozilla |
Vendor: Mozilla |
Product: Firefox ESR Status : PUBLISHED
CVE-2016-9901 Description
HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will be run in the "about:pocket-saved" (unprivileged) page, giving it access to Pocket\'s messaging API through HTML injection. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.