Mozilla SeaMonkey CVE-2013-0751 Weak Authentication Vulnerability

description-logoDescription

Mozilla developer Wesley Johnston reported that when there are two or more iframes on the same HTML page, an iframe is able to see the touch events and their targets that occur within the other iframes on the page. If the iframes are from the same origin, they can also access the properties and methods of the targets of other iframes but same-origin policy (SOP) restricts access across domains. This allows for information leakage and possibilities for cross-site scripting (XSS) if another vulnerability can be used to get around SOP restrictions.

affected-products-logoAffected Applications

SeaMonkey

CVE References

CVE-2013-0751