#VU57882 Improper Restriction of Rendered UI Layers or Frames in Mozilla Firefox and Firefox ESR - CVE-2021-38508

 

#VU57882 Improper Restriction of Rendered UI Layers or Frames in Mozilla Firefox and Firefox ESR - CVE-2021-38508

Published: November 2, 2021


Vulnerability identifier: #VU57882
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2021-38508
CWE-ID: CWE-1021
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Mozilla Firefox
Firefox ESR
Software vendor:
Mozilla

Description

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to Firefox displays the form validity message in the correct location at the same time as a permission prompt (such as for geolocation). The validity message could have obscured the prompt, resulting in the user potentially being tricked into granting the permission.


Remediation

Install updates from vendor's website.

External links