CVE-2014-1485 PUBLISHED

Reported by mozilla · Published February 6, 2014

The Content Security Policy (CSP) implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 operates on XSLT stylesheets according to style-src directives instead of script-src directives, which might allow remote attackers to execute arbitrary XSLT code by leveraging insufficient style-src restrictions.

Affected Products

VendorProductVersions
n/an/an/a
n/an/an/a

Timeline

References

Open in Interactive Console →