Universal Cross-Site Scripting Vulnerability in Firefox for Android by Mozilla
CVE-2021-29953
6.1MEDIUM
Summary
A vulnerability exists in Firefox for Android that enables a malicious webpage to execute attacker-controlled JavaScript in the context of a different domain. This Universal Cross-Site Scripting issue specifically targets Firefox users on Android devices, allowing for potential exploitation and data exposure. Users are encouraged to update to the latest versions to mitigate this risk.
Affected Version(s)
Firefox < 88.0.1
Firefox for Android < 88.1.3
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved