CVE-2023-23601: URL being dragged from cross-origin iframe into same tab triggers navigation
Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-23601?
CVE-2023-23601 is a vulnerability that allows navigations when dragging a URL from a cross-origin iframe into the same tab, which can lead to website spoofing attacks.
Which software versions are affected by CVE-2023-23601?
Firefox versions before 109, Thunderbird versions before 102.7, and Firefox ESR versions before 102.7 are affected by CVE-2023-23601.
What is the severity of CVE-2023-23601?
CVE-2023-23601 has a severity rating of 6.5, which is considered medium.
How can I fix CVE-2023-23601 in Firefox?
To fix CVE-2023-23601 in Firefox, update to version 109 or later.
How can I fix CVE-2023-23601 in Thunderbird?
To fix CVE-2023-23601 in Thunderbird, update to version 102.7 or later.
How can I fix CVE-2023-23601 in Firefox ESR?
To fix CVE-2023-23601 in Firefox ESR, update to version 102.7 or later.