CVE Published: 11/06/2018 |
CVE Updated: 06/08/2024 |
CVE Year: 2016 Source: mozilla |
Vendor: Mozilla |
Product: Firefox Status : PUBLISHED
CVE-2016-9903 Description
Mozilla\'s add-ons SDK had a world-accessible resource with an HTML injection vulnerability. If an additional vulnerability allowed this resource to be loaded as a document it could allow injecting content and script into an add-on\'s context. This vulnerability affects Firefox < 50.1.