CVE-2023-6211

CVSS v3.1 6.5 (Medium)
65% Progress
EPSS 0.05 % (23th)
0.05% Progress
Affected Products 1
Advisories 3

If an attacker needed a user to load an insecure http: page and knew that user had enabled HTTPS-only mode, the attacker could have tricked the user into clicking to grant an HTTPS-only exception if they could get the user to participate in a clicking game. This vulnerability affects Firefox < 120.

Weaknesses
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2023-11-21 15:15:08
(10 months ago)
Updated Date
2024-01-07 11:15:14
(8 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox prior 120.0 version cpe:2.3:a:mozilla:firefox < 120.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...