CVE-2013-1692
Mozilla: Data in the body of XHR HEAD requests leads to CSRF attacks (MFSA 2013-54)
Severity Score
4.3
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not prevent the inclusion of body data in an XMLHttpRequest HEAD request, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a crafted web site.
Mozilla Firefox anterior a v22.0, Firefox ESR v17.x anterior a v17.0.7, Thunderbird anterior a v17.0.7, y Thunderbird ESR v17.x anterior a v17.0.7 no impiden la inclusión de datos del cuerpo en una petición HEAD XMLHttpRequest, lo que hace más fácil para los atacantes remotos realizar ataques de petición en sitios cruzados (CSRF) a través de un sitio web manipulado.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2013-02-13 CVE Reserved
- 2013-06-25 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (18)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/60783 | Vdb Entry | |
https://bugzilla.mozilla.org/show_bug.cgi?id=866915 | X_refsource_confirm | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17096 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | <= 21.0 Search vendor "Mozilla" for product "Firefox" and version " <= 21.0" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | 19.0 Search vendor "Mozilla" for product "Firefox" and version "19.0" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | 19.0.1 Search vendor "Mozilla" for product "Firefox" and version "19.0.1" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | 19.0.2 Search vendor "Mozilla" for product "Firefox" and version "19.0.2" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | 20.0 Search vendor "Mozilla" for product "Firefox" and version "20.0" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | 20.0.1 Search vendor "Mozilla" for product "Firefox" and version "20.0.1" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Esr Search vendor "Mozilla" for product "Firefox Esr" | 17.0 Search vendor "Mozilla" for product "Firefox Esr" and version "17.0" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Esr Search vendor "Mozilla" for product "Firefox Esr" | 17.0.1 Search vendor "Mozilla" for product "Firefox Esr" and version "17.0.1" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Esr Search vendor "Mozilla" for product "Firefox Esr" | 17.0.2 Search vendor "Mozilla" for product "Firefox Esr" and version "17.0.2" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Esr Search vendor "Mozilla" for product "Firefox Esr" | 17.0.3 Search vendor "Mozilla" for product "Firefox Esr" and version "17.0.3" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Esr Search vendor "Mozilla" for product "Firefox Esr" | 17.0.4 Search vendor "Mozilla" for product "Firefox Esr" and version "17.0.4" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Esr Search vendor "Mozilla" for product "Firefox Esr" | 17.0.5 Search vendor "Mozilla" for product "Firefox Esr" and version "17.0.5" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Esr Search vendor "Mozilla" for product "Firefox Esr" | 17.0.6 Search vendor "Mozilla" for product "Firefox Esr" and version "17.0.6" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Search vendor "Mozilla" for product "Thunderbird" | <= 17.0.6 Search vendor "Mozilla" for product "Thunderbird" and version " <= 17.0.6" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Search vendor "Mozilla" for product "Thunderbird" | 17.0 Search vendor "Mozilla" for product "Thunderbird" and version "17.0" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Search vendor "Mozilla" for product "Thunderbird" | 17.0.1 Search vendor "Mozilla" for product "Thunderbird" and version "17.0.1" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Search vendor "Mozilla" for product "Thunderbird" | 17.0.2 Search vendor "Mozilla" for product "Thunderbird" and version "17.0.2" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Search vendor "Mozilla" for product "Thunderbird" | 17.0.3 Search vendor "Mozilla" for product "Thunderbird" and version "17.0.3" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Search vendor "Mozilla" for product "Thunderbird" | 17.0.4 Search vendor "Mozilla" for product "Thunderbird" and version "17.0.4" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Search vendor "Mozilla" for product "Thunderbird" | 17.0.5 Search vendor "Mozilla" for product "Thunderbird" and version "17.0.5" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Esr Search vendor "Mozilla" for product "Thunderbird Esr" | 17.0 Search vendor "Mozilla" for product "Thunderbird Esr" and version "17.0" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Esr Search vendor "Mozilla" for product "Thunderbird Esr" | 17.0.1 Search vendor "Mozilla" for product "Thunderbird Esr" and version "17.0.1" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Esr Search vendor "Mozilla" for product "Thunderbird Esr" | 17.0.2 Search vendor "Mozilla" for product "Thunderbird Esr" and version "17.0.2" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Esr Search vendor "Mozilla" for product "Thunderbird Esr" | 17.0.3 Search vendor "Mozilla" for product "Thunderbird Esr" and version "17.0.3" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Esr Search vendor "Mozilla" for product "Thunderbird Esr" | 17.0.4 Search vendor "Mozilla" for product "Thunderbird Esr" and version "17.0.4" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Esr Search vendor "Mozilla" for product "Thunderbird Esr" | 17.0.5 Search vendor "Mozilla" for product "Thunderbird Esr" and version "17.0.5" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Esr Search vendor "Mozilla" for product "Thunderbird Esr" | 17.0.6 Search vendor "Mozilla" for product "Thunderbird Esr" and version "17.0.6" | - |
Affected
|