← Back to CVE List

CVE-2024-10461

Published: 2024-10-29T13:15Z
Last Modified: 2024-11-04T13:25Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a download, which could allow XSS attacks. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt