Closed Bug 1551937 Opened 6 years ago Closed 6 years ago

Extension Block Request: Add-ons executing remote code

Categories

(Toolkit :: Blocklist Policy Requests, task)

task
Not set
normal

Tracking

()

RESOLVED FIXED

People

(Reporter: zitrobugs, Assigned: Fallen)

Details

Extension name Inspiring Quotes + Daily Quote Tab + Pug Extension
Extension versions affected <all versions>
Platforms affected <all platforms>
Block severity hard

Reason

Remote script injection
Data to website result-spark.com are stored in storage-sync.sqlite

Extension IDs

{ec19994c-c5a5-46d9-bd4d-0fc417c6f4b8}
{a0be7e8d-b0a3-460b-8a52-429c79e49ee2}
{1814dd58-4147-4cca-a0a3-c5aa35966d9c}
Summary: Extension Block Request: Inspiring Quotes → Extension Block Request: Add-ons executing remote code
Assignee: nobody → philipp
Status: NEW → ASSIGNED
Type: defect → task

I’ve reviewed the add-ons and confirmed they are executing remote code.

The block has been staged. Andreas, can you review and push?

Flags: needinfo?(awagner)

Done

Group: blocklist-requests
Status: ASSIGNED → RESOLVED
Closed: 6 years ago
Flags: needinfo?(awagner)
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.