ZeroHour

CVE-2021-29975

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p60
Published
()
Modified
Description

Through a series of DOM manipulations, a message, over which the attacker had control of the text but not HTML or formatting, could be overlaid on top of another domain (with the new domain correctly shown in the address bar) resulting in possible user confusion. This vulnerability affects Firefox < 90.

Vendors
mozilla
Products
firefox
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.