PT-2023-4683 · Mozilla+5 · Firefox+5

Malte Jürgens

·

Published

2023-08-29

·

Updated

2025-03-14

·

CVE-2023-4579

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 117
Description The issue is related to insufficient input validation in the default search engine. This could allow a remote attacker to perform a spoofing attack if a site is maliciously set as the default search engine. Search queries in the default search engine could appear to have been the currently navigated URL if the search query itself was a well-formed URL.
Recommendations For versions prior to 117, update to version 117 or later to resolve the issue. As a temporary workaround, consider restricting the use of the default search engine feature until a patch is applied. Avoid using maliciously configured search engines to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-5213
ALT-PU-2024-13898
ALT-PU-2024-14035
ALT-PU-2024-15840
ALT-PU-2024-4241
BDU:2023-05100
CVE-2023-4579
OESA-2025-1265
OESA-2025-1268
OPENSUSE-SU-2024:13176-1
OPENSUSE-SU-2024:14572-1
ROSA-SA-2024-2371
USN-6320-1

Affected Products

Alt Linux
Astra Linux
Firefox
Linuxmint
Red Os
Ubuntu