Sage vulnerable to arbitrary script execution


Sage is vulnerable to arbitrary script execution.

Note that this vulnerability is different from JVN#30221194.

Sage is an addon for Mozilla Firefox that adds an RSS/Atom feed reader. Sage is vulnerable to arbitrary script execution due to the improper processing during HTML page output based on feed information.
CVSS Severity (What is CVSS?)

CVSS V2 Severity:
Base Metrics 5.8 (Medium) [IPA Score]
  • Access Vector: Network
  • Access Complexity: Medium
  • Authentication: None
  • Confidentiality Impact: Partial
  • Integrity Impact: Partial
  • Availability Impact: None
Affected Products

  • Sage versions prior to 1.4.6


An arbitrary script embedded in an RSS/Atom feed may be executed on the user's Mozilla Firefox.

[Update the software]
Update to the latest version according to the information provided by the developer.

[Apply a workaround]
Until an update can be applied, the workaround below may reduce the impact of this vulnerability:

* Uncheck the option for "Read feed into contents area" in Sage
Vendor Information

mozilla.org contributors
CWE (What is CWE?)

  1. Cross-site Scripting(CWE-79) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2009-4102

  1. JVN : JVN#99203127
  2. National Vulnerability Database (NVD) : CVE-2009-4102
  3. Secunia Advisory : SA37466
  4. SecurityFocus : 37120
  5. ISS X-Force Database : 54396
Revision History

  • [2011/09/02]
      Web page published