#VU108047 Input validation error in Firefox ESR - CVE-2025-4084
Published: April 29, 2025
Firefox ESR
Mozilla
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient insufficient escaping of the ampersand character in the "copy as cURL" feature. A remote attacker can trick the victim into copying a specially crafted URL and execute arbitrary commands on the system.
Note, the vulnerability affects Windows installations only.