Through a series of API calls and redirects, an attacker...
Moderate severity
Unreviewed
Published
Feb 20, 2024
to the GitHub Advisory Database
•
Updated Mar 28, 2025
Description
Published by the National Vulnerability Database
Feb 20, 2024
Published to the GitHub Advisory Database
Feb 20, 2024
Last updated
Mar 28, 2025
Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL shown). This vulnerability affects Firefox < 123 and Firefox ESR < 115.8.
References