nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-origin policy and read XML data from another domain via a cross-domain redirect.
Get an AI-powered plain-language explanation of this vulnerability and remediation steps.
Login to generate AI explanation76 reference(s) from NVD