CVE-2024-26281

Upon scanning a JavaScript URI with the QR code scanner, an attacker could have executed unauthorized scripts on the current top origin sites in the URL bar. This vulnerability affects Firefox for iOS < 123.
Configurations

No configuration.

History

20 Nov 2024, 17:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.7
Summary
  • (es) Al escanear un URI de JavaScript con el escáner de códigos QR, un atacante podría haber ejecutado scripts no autorizados en los principales sitios de origen actuales en la barra de URL. Esta vulnerabilidad afecta a Firefox para iOS &lt; 123.
CWE CWE-79

22 Feb 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-22 15:15

Updated : 2024-11-20 17:35


NVD link : CVE-2024-26281

Mitre link : CVE-2024-26281

CVE.ORG link : CVE-2024-26281


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')