CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.5. It affects Windows, Firefox.
CVE
CVE-2023-28163
Severity
MEDIUM
CVSS
6.5
EPSS
0.80%
Windows Firefox
Original NVD Description
When downloading files through the Save As dialog on Windows with suggested filenames containing environment variable names, Windows would have resolved those in the context of the current user. <br>*This bug only affects Firefox on Windows. Other versions of Firefox are unaffected.*. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
Related CVEs
Other vulnerabilities affecting the same vendor(s)