JavaScript Execution Vulnerability in Hubs Cloud by Mozilla
CVE-2021-29979
6.1MEDIUM
Summary
A vulnerability in Hubs Cloud allows users to download shared content, including HTML and JavaScript files. This poses a significant risk as it may enable the execution of malicious JavaScript within the primary hosting domain of the Hub Cloud instance, potentially compromising user security and data integrity.
Affected Version(s)
Hubs Cloud < unspecified
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved