Security Advisory

CVE-2021-23984

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-03-31 13:41:34
Last updated 2024-08-03 19:14:10
Assigner mozilla
State PUBLISHED

Description

A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address bar should not be fully controllable, but in this situation was. This could have been used to spoof a website and attempt to trick the user into providing credentials. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.