CVE-2021-23959Cross-site Scripting in Mozilla Firefox

Severity
6.1MEDIUMNVD
EPSS
0.3%
top 46.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 26
Latest updateMay 24

Description

An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the address bar. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 85.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

CVEListV5mozilla/firefox< 85
NVDmozilla/firefox< 85.0
mozillamozilla/firefox

🔴Vulnerability Details

1
GHSA
GHSA-f3g9-x4jw-849g: An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the address bar2022-05-24

📋Vendor Advisories

2
Debian
CVE-2021-23959: firefox - An XSS bug in internal error pages could have led to various spoofing attacks, i...2021
Mozilla
Mozilla Foundation Security Advisory 2021-03: CVE-2021-23959