CVE-2015-7187

Severity CVSS v4.0:
Pending analysis
Type:
CWE-254 Security Features
Publication date:
05/11/2015
Last modified:
12/04/2025

Description

The Add-on SDK in Mozilla Firefox before 42.0 misinterprets a "script: false" panel setting, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via inline JavaScript code that is executed within a third-party extension.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 41.0.2 (including)