PT-2023-6526 · Mozilla · Firefox

Irwan

·

Publicado

2023-10-24

·

Atualizado

2024-01-07

·

CVE-2023-5758

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Firefox for iOS versions prior to 119
Description The issue is related to the reader mode in Firefox, where the structure of a web page is not properly protected, allowing for potential exploitation. This could lead to a reflected Cross-Site Scripting (XSS) attack, where an attacker-controlled script could execute when a page is opened in reader mode. The attack is conducted through a redirect URL.
Recommendations For Firefox for iOS versions prior to 119: Update to version 119 or later to resolve the issue. As a temporary workaround, consider avoiding the use of reader mode until the update is applied. Restrict access to potentially malicious websites to minimize the risk of exploitation.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-07273
CVE-2023-5758

Produtos afetados

Firefox