Mozilla Firefox Vulnerability Allows Phishing Attacks Through Screenshots

CVE-2024-5689
4.3MEDIUM

Key Information

Vendor
Mozilla
Status
Firefox
Vendor
CVE Published:
11 June 2024

Summary

In addition to detecting when a user was taking a screenshot (XXX), a website was able to overlay the 'My Shots' button that appeared, and direct the user to a replica Firefox Screenshots page that could be used for phishing. This vulnerability affects Firefox < 127.

Affected Version(s)

Firefox < 127

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database

Credit

Fabian Fäßler
.