Closed Bug 1773730 Opened 2 years ago Closed 2 years ago

UXSS via PrototypeMap::createEmptyStructure

Categories

(Firefox :: Security, defect)

defect

Tracking

()

RESOLVED DUPLICATE of bug 1773732

People

(Reporter: adonkidz7, Unassigned)

References

()

Details

(Keywords: reporter-external, Whiteboard: [reporter-external] [client-bounty-form] [verif?])

  1. open the browser (chrome, firefox, ms edge)
  2. go to https://www.w3schools.com/html/tryit.asp?filename=tryhtml_basic
  3. then, enter the code you have generated in w3schools, jsfiddle, or codepen io
  4. run the code and you can see the uXSS executed via w3schools, jsfiddle, and codepen io
  5. after you run the code, only firefox suffered damage like a DOS attack

I'm duping this to the newer bug because that has more information.

Status: UNCONFIRMED → RESOLVED
Closed: 2 years ago
Resolution: --- → DUPLICATE
Group: firefox-core-security
You need to log in before you can comment on or make changes to this bug.