CVE-2021-23959 — Cross-site Scripting in Mozilla Firefox
Severity
6.1MEDIUMNVD
EPSS
0.3%
top 46.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 26
Latest updateMay 24
Description
An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the address bar. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 85.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7
Affected Packages4 packages
🔴Vulnerability Details
1GHSA▶
GHSA-f3g9-x4jw-849g: An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the address bar↗2022-05-24