CVE-2025-13013
BaseFortify
Publication date: 2025-11-11
Last updated on: 2026-04-13
Assigner: Mozilla Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mozilla | firefox | From 60.9.0 (exc) |
| mozilla | firefox | From 60.9.0 (exc) |
| mozilla | firefox | From 60.9.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-288 | The product requires authentication, but the product has an alternate path or channel that does not require authentication. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a mitigation bypass in the DOM: Core & HTML component affecting certain versions of Firefox and Firefox ESR. It means that a security measure intended to protect the Document Object Model (DOM) in these browsers can be bypassed, potentially allowing unintended behavior or exploitation.
How can this vulnerability impact me? :
The impact of this vulnerability could include exposure to security risks such as unauthorized access or manipulation of web content within affected Firefox browsers. This could lead to compromised user data or browser behavior.