#VU56373 Input validation error in Mozilla Firefox and Firefox ESR - CVE-2021-38492
Published: September 7, 2021 / Updated: September 8, 2021
Mozilla Firefox
Firefox ESR
Mozilla
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient validation of user-supplied input when delegating navigations to the operating system. Firefox accept the mk scheme, which allows a remote attacker to launch pages and execute scripts in Internet Explorer in unprivileged mode.