CVE-2024-26284
published 2024-02-22CVE-2024-26284: Utilizing a 302 redirect, an attacker could have conducted a Universal Cross-Site Scripting (UXSS) on a victim website, if the victim had a link to the…
PriorityP424medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.32%
24.4th percentile
Utilizing a 302 redirect, an attacker could have conducted a Universal Cross-Site Scripting (UXSS) on a victim website, if the victim had a link to the attacker's website. This vulnerability affects Focus for iOS < 123.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | — | — |
| mozilla | firefox_focus | < 123.0 | 123.0 |
| mozilla | focus_for_ios | >= unspecified < 123 | 123 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Mozilla
Mozilla Foundation Security Advisory 2024-10: CVE-2024-26284
vendor_mozilla·CVSS 6.1
CVE-2024-26284 [MEDIUM] Mozilla Foundation Security Advisory 2024-10: CVE-2024-26284
Mozilla Foundation Security Advisory 2024-10
CVE: CVE-2024-26284
Product: Focus for iOS
Impact: high
Fixed in: Focus for iOS 123
GHSA
GHSA-3q83-x89h-m869: Utilizing a 302 redirect, an attacker could have conducted a Universal Cross-Site Scripting (UXSS) on a victim website, if the victim had a link to th
ghsa_unreviewed·2024-02-22
CVE-2024-26284 [MEDIUM] CWE-79 GHSA-3q83-x89h-m869: Utilizing a 302 redirect, an attacker could have conducted a Universal Cross-Site Scripting (UXSS) on a victim website, if the victim had a link to th
Utilizing a 302 redirect, an attacker could have conducted a Universal Cross-Site Scripting (UXSS) on a victim website, if the victim had a link to the attacker's website. This vulnerability affects Focus for iOS < 123.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-02-22
Published