Same Origin Policy Bypass in Mozilla Firefox 49.0

Same Origin Policy Bypass in Mozilla Firefox 49.0

CVE-2016-5283 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier in the SRC attribute of an IFRAME element, leading to insufficient restrictions on link-color information after a document is resized.

Learn more about our Web Application Penetration Testing UK.