Lucene search

K
cveMozillaCVE-2024-26284
HistoryFeb 22, 2024 - 3:15 p.m.

CVE-2024-26284

2024-02-2215:15:08
mozilla
web.nvd.nist.gov
5289
cve-2024-26284
302 redirect
universal cross-site scripting
uxss
focus for ios
vulnerability
nvd

AI Score

5.8

Confidence

High

EPSS

0

Percentile

9.0%

Utilizing a 302 redirect, an attacker could have conducted a Universal Cross-Site Scripting (UXSS) on a victim website, if the victim had a link to the attacker’s website. This vulnerability affects Focus for iOS < 123.

Affected configurations

Vulners
Node
mozillafocusRange123android
VendorProductVersionCPE
mozillafocus*cpe:2.3:a:mozilla:focus:*:*:*:*:*:android:*:*

CNA Affected

[
  {
    "product": "Focus for iOS",
    "vendor": "Mozilla",
    "versions": [
      {
        "lessThan": "123",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

AI Score

5.8

Confidence

High

EPSS

0

Percentile

9.0%

Related for CVE-2024-26284