CVE-2023-37205 is a URL spoofing vulnerability affecting Mozilla Firefox versions prior to 115, where the use of right-to-left (RTL) Arabic characters in the address bar could mislead users about the true destination of a link. Rated Medium severity (CVSS 6.5), this vulnerability requires user interaction (UI:R) but can lead to high integrity impact (I:H) if exploited, as an attacker could trick users into visiting malicious sites. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 115.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 115CPE match | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.