CVE-2023-25728

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jun 2, 2023
Updated: Jan 10, 2025
CWE ID 203

Summary

CVE-2023-25728 is a vulnerability affecting Firefox versions prior to 110, Thunderbird versions below 102.8, and Firefox ESR versions below 102.8. This issue lies in the handling of the <code>Content-Security-Policy-Report-Only</code> header. An attacker can manipulate a webpage to trigger a redirect from an iframe, revealing the unredacted URI of the child iframe to the attacker, potentially leading to sensitive data exposure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share