SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-2060

Cross-zone scripting vulnerability in the Wizz RSS Reader before 2.1.9 extension to Mozilla Firefox allows remote attackers to execute arbitrary Javascript in the browser chrome via the RSS feed DOM.

MEDIUM 6.8EPSS 3.17%

Does this matter?

Lower severity and a low EPSS score (3.17%). Track it; it rarely justifies an emergency change on its own.

Description

Cross-zone scripting vulnerability in the Wizz RSS Reader before 2.1.9 extension to Mozilla Firefox allows remote attackers to execute arbitrary Javascript in the browser chrome via the RSS feed DOM.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
3.17% probability · 87th percentile
CISA KEV
Not listed
Affected
wizz computers/wizz rss reader
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.