CVE-2024-26284: XSS
Published Feb 19, 2024
·Updated
Utilizing a 302 redirect, an attacker could have conducted a Universal Cross-Site Scripting (UXSS) on a victim website, if the victim had a link to the attacker's website.
Affected Software
3 affected components
All of the following
Mozilla Focus=123
Apple iOS
Mozilla Firefox Focus Iphone Os<123.0
Event History
Feb 19, 2024
CVE Published
via Mozilla·12:00 AM
Feb 22, 2024
CVE Published
via MITRE·02:56 PM
Data Sourced
via MITRE·02:56 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-26284?
CVE-2024-26284 presents a high risk due to the potential for Universal Cross-Site Scripting (UXSS) attacks.
2
How do I fix CVE-2024-26284?
To fix CVE-2024-26284, update to the latest version of Mozilla Firefox Focus or affected Apple iOS software.
3
Who is affected by CVE-2024-26284?
CVE-2024-26284 affects users of Mozilla Firefox Focus version 123 and certain versions of Apple iOS.
4
What kind of attack can be executed with CVE-2024-26284?
CVE-2024-26284 allows an attacker to perform Universal Cross-Site Scripting (UXSS) due to insecure 302 redirects.
5
Is CVE-2024-26284 a widespread issue?
The impact of CVE-2024-26284 may vary, primarily affecting users of specific versions of Mozilla Focus and Apple iOS.