CVE-2023-6869 — Mozilla Firefox vulnerability
10 documents7 sources
Severity
6.5MEDIUMNVD
OSV4.3
EPSS
0.2%
top 59.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 19
Latest updateJan 11
Description
A ` ` element could have been manipulated to paint content outside of a sandboxed iframe. This could allow untrusted content to display under the guise of trusted content. This vulnerability affects Firefox < 121.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6
Affected Packages3 packages
🔴Vulnerability Details
5OSV▶
CVE-2023-6869: A ` ` element could have been manipulated to paint content outside of a sandboxed iframe↗2023-12-20
CVEList▶
CVE-2023-6869: A ` ` element could have been manipulated to paint content outside of a sandboxed iframe↗2023-12-19
GHSA▶
GHSA-8c4w-xw52-85px: A `` element could have been manipulated to paint content outside of a sandboxed iframe↗2023-12-19