CVE-2024-9397

6.1MEDIUM

A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 12

发布于: 10/1/2024更新于: 3/18/2025

描述

A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.

AI分析AI驱动

受影响产品

mozillafirefox
mozillafirefox_esr
mozillathunderbird
mozillathunderbird
129.0
mozillathunderbird
129.0
mozillathunderbird
129.0
mozillathunderbird
129.0
mozillathunderbird
129.0
mozillathunderbird
129.0

参考资料