First published: Tue Dec 19 2023(Updated: )
A `<dialog>` element could have been manipulated to paint content outside of a sandboxed iframe. This could allow untrusted content to display under the guise of trusted content. This vulnerability affects Firefox < 121.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <121 | 121 |
Firefox | <121.0 | |
debian/firefox | 137.0.1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-6869 has been classified with a moderate severity level due to its potential to deceive users by allowing untrusted content to appear as trusted.
To fix CVE-2023-6869, update your Firefox browser to version 121 or later.
CVE-2023-6869 affects all versions of Firefox prior to version 121.
CVE-2023-6869 can be exploited to manipulate a <dialog> element to paint content outside of a sandboxed iframe.
There are no known effective workarounds for CVE-2023-6869; updating to a secure version of Firefox is recommended.