Cross-Site Scripting Vulnerability in Mozilla Firefox OS Internationalization Feature
CVE-2015-8510
6.1MEDIUM
What is CVE-2015-8510?
A cross-site scripting (XSS) vulnerability exists in the internationalization feature of the default homescreen app in Mozilla Firefox OS. Versions prior to 2.5 allow a user-assisted remote attacker to exploit this flaw by injecting malicious web scripts or HTML through a specially crafted website. This occurs during the 'Add to home screen' bookmarking process, potentially compromising users' security. It emphasizes the importance of maintaining updated software to mitigate security risks.