CVE-2022-31743

MEDIUM

Firefox < 101.0 - Cross-Site Scripting via HTML Comment Parsing Incongruity

Title source: llm
STIX 2.1

Description

Firefox's HTML parser did not correctly interpret HTML comment tags, resulting in an incongruity with other browsers. This could have been used to escape HTML comments on pages that put user-controlled data in them. This vulnerability affects Firefox < 101.

References (2)

Core 2
Core References
Issue Tracking, Permissions Required, Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=1747388

Scores

CVSS v3 6.5
EPSS 0.0062
EPSS Percentile 70.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
mozilla/firefox < 101.0
Published Dec 22, 2022
Tracked Since Feb 18, 2026