CVE-2021-23959
published 2021-02-26CVE-2021-23959: An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the address bar. Note: This issue only affected…
PriorityP423medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.57%
43.8th percentile
An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the address bar. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 85.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| mozilla | firefox | < 85 | 85 |
| mozilla | firefox | < 85.0 | 85.0 |
| mozilla | firefox | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_debian6.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2021-23959: firefox - An XSS bug in internal error pages could have led to various spoofing attacks, i...
vendor_debian·2021·CVSS 6.1
CVE-2021-23959 [MEDIUM] CVE-2021-23959: firefox - An XSS bug in internal error pages could have led to various spoofing attacks, i...
An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the address bar. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 85.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2021-03: CVE-2021-23959
vendor_mozilla·CVSS 6.1
CVE-2021-23959 [MEDIUM] Mozilla Foundation Security Advisory 2021-03: CVE-2021-23959
Mozilla Foundation Security Advisory 2021-03
CVE: CVE-2021-23959
Product: Firefox
Impact: high
Fixed in: Firefox 85
GHSA
GHSA-f3g9-x4jw-849g: An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the address bar
ghsa_unreviewed·2022-05-24
CVE-2021-23959 [MEDIUM] CWE-79 GHSA-f3g9-x4jw-849g: An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the address bar
An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the address bar. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 85.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-02-26
Published