Tuesday, October 15, 2019

Firefox Blocks Inline and Eval JavaScript on Internal Pages to Prevent Injection Attacks

In an effort to mitigate a large class of potential cross-site scripting issues in Firefox, Mozilla has blocked execution of all inline scripts and potentially dangerous eval-like functions for built-in "about: pages" that are the gateway to sensitive preferences, settings, and statics of the browser. Firefox browser has 45 such internal locally-hosted about pages, some of which are listed

from The Hacker News https://ift.tt/2MfDDWA

Labels:

0 Comments:

Post a Comment

Subscribe to Post Comments [Atom]

<< Home