Closed Bug 1320447 Opened 8 years ago Closed 8 years ago

UXSS using bookmark

Categories

(Firefox :: Untriaged, defect)

1.0 Branch
defect
Not set
normal

Tracking

()

RESOLVED DUPLICATE of bug 371923

People

(Reporter: s.h.h.n.j.k, Unassigned)

References

Details

Attachments

(1 file)

Attached video firefox.mov
User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.98 Safari/537.36 Steps to reproduce: 1. Go to https://jsfiddle.net/6om4ddzp/9/ 2. Select Drag me and drop it to bookmark tool bar. 3. Clicking added bookmark will execute javascript on current website Actual results: UXSS via javascript: URL bookmark Expected results: Do not allow javascript: URL on bookmark
Group: firefox-core-security
Status: UNCONFIRMED → RESOLVED
Closed: 8 years ago
Resolution: --- → DUPLICATE
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: