CVE-2021-23959 describes a cross-site scripting (XSS) vulnerability found in internal error pages of Firefox for Android versions prior to 85. This flaw could enable various spoofing attacks, including manipulation of error pages and the address bar. Rated as Medium severity (CVSS 6.1), it requires user interaction and could lead to low impact on confidentiality and integrity. There is no evidence of active exploitation, and public exploit code or Metasploit modules are unavailable, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 85.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:android:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.