CVE Published: 22/12/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: mozilla |
Vendor: Mozilla |
Product: Firefox ESR Status : PUBLISHED
CVE-2022-40956 Description
When injecting an HTML base element, some requests would ignore the CSP\'s base-uri settings and accept the injected element\'s base instead. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.