#VU64753 Insufficient UI Warning of Dangerous Operations in Mozilla Firefox - CVE-2022-34482
Published: June 28, 2022
Mozilla Firefox
Mozilla
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient UI warning when performing drag and drop operations. A remote attacker can trick the victim to drag and drop an image to a filesystem, manipulate the resulting filename to contain executable extension and execute arbitrary application on the system.