Mozilla Firefox Vulnerability Allows XSS Attacks
CVE-2024-10461
6.1MEDIUM
Key Information:
- Vendor
Mozilla
- Vendor
- CVE Published:
- 29 October 2024
What is CVE-2024-10461?
In multipart/x-mixed-replace responses, Content-Disposition: attachment in the response header was not respected and did not force a download, which could allow XSS attacks. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
Affected Version(s)
Firefox < 132
Firefox ESR < 128.4
Thunderbird < 128.4