CVE-2021-23959: XSS
An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the address bar. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 85.
Other sources
An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the address bar.Note: This issue only affected Firefox for Android. Other operating systems are unaffected.
— Mozilla
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2021-23959?
CVE-2021-23959 is classified as a moderate severity vulnerability due to its potential for spoofing attacks.
How do I fix CVE-2021-23959?
To fix CVE-2021-23959, update your Firefox for Android to version 85 or later.
Who is affected by CVE-2021-23959?
CVE-2021-23959 specifically affects users of Firefox for Android on versions prior to 85.
What type of vulnerability is CVE-2021-23959?
CVE-2021-23959 is an XSS (Cross-Site Scripting) vulnerability found in internal error pages of Firefox for Android.
Can I be attacked by CVE-2021-23959 on other operating systems?
No, CVE-2021-23959 only affects Firefox for Android, and other operating systems are not impacted.