PT-2023-6526 · Mozilla · Firefox

Irwan

·

Published

2023-10-24

·

Updated

2024-01-07

·

CVE-2023-5758

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Firefox for iOS versions prior to 119
Description The issue is related to the reader mode in Firefox, where the structure of a web page is not properly protected, allowing for potential exploitation. This could lead to a reflected Cross-Site Scripting (XSS) attack, where an attacker-controlled script could execute when a page is opened in reader mode. The attack is conducted through a redirect URL.
Recommendations For Firefox for iOS versions prior to 119: Update to version 119 or later to resolve the issue. As a temporary workaround, consider avoiding the use of reader mode until the update is applied. Restrict access to potentially malicious websites to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-07273
CVE-2023-5758

Affected Products

Firefox