CVE-2021-43544Cross-site Scripting in Mozilla Firefox

Severity
6.1MEDIUMNVD
EPSS
0.4%
top 40.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 8
Latest updateDec 13

Description

When receiving a URL through a SEND intent, Firefox would have searched for the text, but subsequent usages of the address bar might have caused the URL to load unintentionally, which could lead to XSS and spoofing attacks. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 95.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

CVEListV5mozilla/firefoxunspecified95
NVDmozilla/firefox< 95.0
mozillamozilla/firefox

🔴Vulnerability Details

1
GHSA
GHSA-7w2r-8gq9-28xx: When receiving a URL through a SEND intent, Firefox would have searched for the text, but subsequent usages of the address bar might have caused the U2021-12-09

📋Vendor Advisories

2
Debian
CVE-2021-43544: firefox - When receiving a URL through a SEND intent, Firefox would have searched for the ...2021
Mozilla
Mozilla Foundation Security Advisory 2021-52: CVE-2021-43544

💬Community

1
Bugzilla
Receiving a malicious javascript URL as text via a SEND intent may cause XSS2021-12-13