| The navigator.sendBeacon implementation in Mozilla Firefox before
35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and
SeaMonkey before 2.32 omits the CORS Origin header, which allows
remote attackers to bypass intended CORS access-control checks and
conduct cross-site request forgery (CSRF) attacks via a crafted web
site.
|