CVE-2016-2820

MEDIUM

Mozilla Firefox < 45.0.2 - Improper Access Control

Title source: rule

Description

The Firefox Health Reports (aka FHR or about:healthreport) feature in Mozilla Firefox before 46.0 does not properly restrict the origin of events, which makes it easier for remote attackers to modify sharing preferences by leveraging access to the remote-report IFRAME element.

Scores

CVSS v3 4.3
EPSS 0.0042
EPSS Percentile 61.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Classification

CWE
CWE-284
Status draft

Affected Products (1)

mozilla/firefox < 45.0.2

Timeline

Published Apr 30, 2016
Tracked Since Feb 18, 2026