The COPPA error page in the Accounts setup dialog in Mozilla Firefox OS before 2.2 embeds content from an external web server URL into the System process, which allows man-in-the-middle attackers to bypass intended access restrictions by spoofing that server.
2015-08-08T00:59:06.953
2025-04-12T10:46:40.837
Deferred
CVSSv2: 3.3 (LOW)
AV:A/AC:L/Au:N/C:N/I:P/A:N
6.5
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | mozilla | firefox_os | ≤ 2.1.0 | Yes |