CVE-2023-37203: Mozilla Firefox
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Insufficient validation in the Drag and Drop API in conjunction with social engineering, may have allowed an attacker to trick end-users into creating a shortcut to local system files. This could have been leveraged to execute arbitrary code. This vulnerability affects Firefox < 115.
Affected products
- Mozilla Firefox: before 115.0 (fixed in 115.0)
Published 2023-07-05. Last modified 2026-06-17.