Security News > 2019 > October > Firefox Blocks Inline and Eval JavaScript on Internal Pages to Prevent Injection Attacks
2019-10-15 10:49
In an effort to mitigate a large class of potential cross-site scripting issues in Firefox, Mozilla has blocked execution of all inline scripts and potentially dangerous eval-like functions for built-in "about: pages" that are the gateway to sensitive preferences, settings, and statics of the browser. Firefox browser has 45 such internal locally-hosted about pages, some of which are listed
News URL
http://feedproxy.google.com/~r/TheHackersNews/~3/Ru9Q3eYJaHE/firefox-javascript-injection.html