CVE-2021-43530

MEDIUM

Firefox <94 - XSS

Title source: llm
STIX 2.1

Description

A Universal XSS vulnerability was present in Firefox for Android resulting from improper sanitization when processing a URL scanned from a QR code. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 94.

Exploits (1)

nomisec WRITEUP 1 stars
by hfh86 · poc
https://github.com/hfh86/CVE-2021-43530-UXSS-On-QRcode-Reader-

References (2)

Core 2
Core References
Issue Tracking, Permissions Required x_refsource_misc
https://bugzilla.mozilla.org/show_bug.cgi?id=1736886

Scores

CVSS v3 6.1
EPSS 0.0604
EPSS Percentile 90.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
mozilla/firefox < 94.0
Published Dec 08, 2021
Tracked Since Feb 18, 2026