First published: Mon Feb 19 2024(Updated: )
Utilizing a 302 redirect, an attacker could have conducted a Universal Cross-Site Scripting (UXSS) on a victim website, if the victim had a link to the attacker's website.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox Focus | <123.0 | |
All of | ||
Mozilla Focus | =123 | |
Apple iOS, iPadOS, and watchOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-26284 presents a high risk due to the potential for Universal Cross-Site Scripting (UXSS) attacks.
To fix CVE-2024-26284, update to the latest version of Mozilla Firefox Focus or affected Apple iOS software.
CVE-2024-26284 affects users of Mozilla Firefox Focus version 123 and certain versions of Apple iOS.
CVE-2024-26284 allows an attacker to perform Universal Cross-Site Scripting (UXSS) due to insecure 302 redirects.
The impact of CVE-2024-26284 may vary, primarily affecting users of specific versions of Mozilla Focus and Apple iOS.