Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-8897

Опубликовано: 17 сент. 2024
Источник: nvd
CVSS3: 6.1
EPSS Низкий

Описание

Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a trusted site, may be able to spoof the address bar contents. This can lead to a malicious site to appear to have the same URL as the trusted site. This bug only affects Firefox for Android. Other versions of Firefox are unaffected. This vulnerability affects Firefox for Android < 130.0.1.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
Версия до 130.0.1 (исключая)
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

EPSS

Процентиль: 33%
0.00125
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-601
CWE-601

Связанные уязвимости

CVSS3: 6.1
debian
10 месяцев назад

Under certain conditions, an attacker with the ability to redirect use ...

CVSS3: 6.1
github
10 месяцев назад

Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a trusted site, may be able to spoof the address bar contents. This can lead to a malicious site to appear to have the same URL as the trusted site. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox for Android < 130.0.1.

CVSS3: 6.1
fstec
10 месяцев назад

Уязвимость браузера Mozilla Firefox операционных систем Android, связанная с использованием открытой переадресации, позволяющая нарушителю перенаправить пользователя на произвольный URL-адрес

EPSS

Процентиль: 33%
0.00125
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-601
CWE-601