components/sessionstore/src/nsSessionStore.js in Mozilla Firefox before 3.0.6 does not block changes of INPUT elements to type="file" during tab restoration, which allows user-assisted remote attackers to read arbitrary files on a client machine via a crafted INPUT element.
Get an AI-powered plain-language explanation of this vulnerability and remediation steps.
Login to generate AI explanation54 reference(s) from NVD