6.5
CVE-2025-5271
- EPSS 0.28%
- Veröffentlicht 27.05.2025 12:29:29
- Zuletzt bearbeitet 30.09.2026 18:10:00
- Erkennungen
Devtools' preview ignored CSP headers
Previewing a response in Devtools ignored CSP headers, which could have allowed content injection attacks. This vulnerability was fixed in Firefox 139 and Thunderbird 139.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.28% | 0.209 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 6.5 | 3.9 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
|
CWE-116 Improper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
https://www.mozilla.org/security/advisories/mfsa2025-42/
https://bugzilla.mozilla.org/show_bug.cgi?id=1920348
https://www.mozilla.org/security/advisories/mfsa2025-45/