PT-2023-6526 · Mozilla · Firefox
Irwan
·
Published
2023-10-24
·
Updated
2024-01-07
·
CVE-2023-5758
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Firefox for iOS versions prior to 119
Description
The issue is related to the reader mode in Firefox, where the structure of a web page is not properly protected, allowing for potential exploitation. This could lead to a reflected Cross-Site Scripting (XSS) attack, where an attacker-controlled script could execute when a page is opened in reader mode. The attack is conducted through a redirect URL.
Recommendations
For Firefox for iOS versions prior to 119: Update to version 119 or later to resolve the issue. As a temporary workaround, consider avoiding the use of reader mode until the update is applied. Restrict access to potentially malicious websites to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Firefox