CVE-2021-23984

CVSS v3.1 6.5 (Medium)
65% Progress
CVSS v2.0 4.3 (Medium)
43% Progress
EPSS 0.13 % (48th)
0.13% Progress
Affected Products 3
Advisories 28

A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address bar should not be fully controllable, but in this situation was. This could have been used to spoof a website and attempt to trick the user into providing credentials. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.

Weaknesses
CWE-290
Authentication Bypass by Spoofing
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2021-03-31 14:15:19
(3 years ago)
Updated Date
2021-08-06 18:18:41
(3 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox prior 87.0 version cpe:2.3:a:mozilla:firefox < 87.0
  Mozilla Firefox Esr prior 78.9 version cpe:2.3:a:mozilla:firefox_esr < 78.9
  Mozilla Thunderbird prior 78.9 version cpe:2.3:a:mozilla:thunderbird < 78.9
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...