CVE-2024-26281

Upon scanning a JavaScript URI with the QR code scanner, an attacker could have executed unauthorized scripts on the current top origin sites in the URL bar. This vulnerability affects Firefox for iOS < 123.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:*

History

27 Mar 2025, 14:45

Type Values Removed Values Added
First Time Mozilla
Mozilla firefox
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:*
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1868005 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1868005 - Issue Tracking
References () https://www.mozilla.org/security/advisories/mfsa2024-08/ - () https://www.mozilla.org/security/advisories/mfsa2024-08/ - Vendor Advisory

21 Nov 2024, 09:02

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1868005 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1868005 -
References () https://www.mozilla.org/security/advisories/mfsa2024-08/ - () https://www.mozilla.org/security/advisories/mfsa2024-08/ -

20 Nov 2024, 17:35

Type Values Removed Values Added
Summary
  • (es) Al escanear un URI de JavaScript con el escáner de códigos QR, un atacante podría haber ejecutado scripts no autorizados en los principales sitios de origen actuales en la barra de URL. Esta vulnerabilidad afecta a Firefox para iOS &lt; 123.
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.7

22 Feb 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-22 15:15

Updated : 2025-03-27 14:45


NVD link : CVE-2024-26281

Mitre link : CVE-2024-26281

CVE.ORG link : CVE-2024-26281


JSON object : View

Products Affected

mozilla

  • firefox
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')