Back

MEDIUM

Mozilla: Full local path of files is available to web pages after drag and drop (MFSA 2016-85)

Published Sep 22, 2016

Description

Mozilla Firefox before 49.0 allows user-assisted remote attackers to obtain sensitive full-pathname information during a local-file drag-and-drop operation via crafted JavaScript code.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Sep 22, 2016
Updated Aug 6, 2024
Reserved Jun 3, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 20, 2016