Cross-Site Scripting Vulnerability in Bugzilla Flash Component by YUI
CVE-2012-5883

Currently unrated

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
16 November 2012

What is CVE-2012-5883?

A cross-site scripting vulnerability exists within the Flash component of YUI version 2.8.0 to 2.9.0, utilized in Bugzilla versions 3.7.x and 4.0.x prior to 4.0.9, as well as in versions 4.1.x, 4.2.x, 4.3.x, and 4.4.x before their respective security releases. This vulnerability permits remote attackers to inject arbitrary web scripts or HTML through vectors associated with the swfstore.swf file. This security issue shares similarities with a previously documented vulnerability, posing risks for applications relying on the vulnerable versions.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.