If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing attack. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
Link | Tags |
---|---|
https://bugzilla.mozilla.org/show_bug.cgi?id=1907032 | issue tracking permissions required |
https://bugzilla.mozilla.org/show_bug.cgi?id=1909163 | issue tracking permissions required |
https://bugzilla.mozilla.org/show_bug.cgi?id=1909529 | issue tracking permissions required |
https://www.mozilla.org/security/advisories/mfsa2024-39/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2024-40/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2024-43/ |