CVE-2021-29944: XSS
Lack of escaping allowed HTML injection when a webpage was viewed in Reader View. While a Content Security Policy prevents direct code execution, HTML injection is still possible. Note: This issue only affected Firefox for Android. Other operating systems are unaffected.. This vulnerability affects Firefox < 88.
Other sources
Lack of escaping allowed HTML injection when a webpage was viewed in Reader View. While a Content Security Policy prevents direct code execution, HTML injection is still possible.Note: This issue only affected Firefox for Android. Other operating systems are unaffected.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2021-29944?
The severity of CVE-2021-29944 is considered moderate due to the potential for HTML injection.
How do I fix CVE-2021-29944?
To fix CVE-2021-29944, update Firefox for Android to version 88 or later.
Who is affected by CVE-2021-29944?
CVE-2021-29944 specifically affects users of Firefox for Android version prior to 88.
What type of vulnerability is CVE-2021-29944?
CVE-2021-29944 is an HTML injection vulnerability due to lack of proper escaping.
Can CVE-2021-29944 lead to code execution?
No, CVE-2021-29944 does not allow for direct code execution but enables HTML injection.