First published: Mon Apr 19 2021(Updated: )
Lack of escaping allowed HTML injection when a webpage was viewed in Reader View. While a Content Security Policy prevents direct code execution, HTML injection is still possible. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 88.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <88 | 88 |
Firefox | <88.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2021-29944 is considered moderate due to the potential for HTML injection.
To fix CVE-2021-29944, update Firefox for Android to version 88 or later.
CVE-2021-29944 specifically affects users of Firefox for Android version prior to 88.
CVE-2021-29944 is an HTML injection vulnerability due to lack of proper escaping.
No, CVE-2021-29944 does not allow for direct code execution but enables HTML injection.