CVE-2023-4579: Persisted search terms were formatted as URLs
Last updated 24 July 2024
Other sources
Search queries in the default search engine could appear to have been the currently navigated URL if the search query itself was a well formed URL. This could have led to a site spoofing another if it had been maliciously set as the default search engine.
— Mozilla
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-4579?
CVE-2023-4579 is a vulnerability in Firefox where search queries in the default search engine can appear to have been the currently navigated URL.
What is the severity of CVE-2023-4579?
The severity of CVE-2023-4579 is medium with a CVSS score of 3.1.
Which software versions are affected by CVE-2023-4579?
Firefox versions prior to 117.0 are affected by CVE-2023-4579.
How can CVE-2023-4579 be exploited?
CVE-2023-4579 can be exploited by setting a malicious site as the default search engine and using a well-formed URL as a search query.
Where can I find more information about CVE-2023-4579?
You can find more information about CVE-2023-4579 on the CVE Mitre, Ubuntu Security Notices, and NVD websites.