Browser

Cross-Site Scripting (XSS)

Firefox IOS QR Code Reader XSS

Firefox IOS QR Code Reader XSS This vulnerability allows an attacker to steal victim’s cookies, personal data and other valuable information from different origins just by scanning a QR code

6.1
/ 10
Medium
CVSS v3.1
ADVISORY ID
PS27
PUBLISHED
2022-10-02
CVE IDs
CVE-2019-17003
VENDORS
Mozilla
PUBLIC EXPLOIT
PoC public
CWE
CWE-79
PRODUCT
Firefox for iOS
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Firefox IOS QR Code Reader XSS

This vulnerability allows an attacker to steal victim’s cookies, personal data and other valuable information from different origins just by scanning a QR code

Vulnerability details

Vulnerability details

CVE-2019-17003
CWE-79
Medium | 6.1

Firefox IOS QR Code Reader XSS This vulnerability allows an attacker to steal victim’s cookies, personal data and other valuable information from different origins just by scanning a QR code

Auth:
None (remote, user interaction required)
Impact:
Limited data disclosure, limited data tampering; impact extends beyond the vulnerable component
DISCLOSURE

Disclosure timeline

2019-07-18 reported to the vendor

2019-10-22 fixed released by the vendor

Credits

Nikhil Mittal