PoC Index

CVE-2021-23999

HIGH 8.8EPSS 1.3%

If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges that should not be granted to web content. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.

CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
1.28% chance of exploitation in the next 30 days, 68th percentile
Published
2021-06-24
Updated
2024-08-03

Proof-of-concept exploits (1)

References

Related