CVE-2024-11700

HIGH

Firefox < 133 - CSRF

Title source: llm
STIX 2.1

Description

Malicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to users unknowingly approving the launch of external applications, potentially exposing them to underlying vulnerabilities. This vulnerability affects Firefox < 133 and Thunderbird < 133.

Scores

CVSS v3 8.1
EPSS 0.0027
EPSS Percentile 50.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-1021
Status published
Products (2)
mozilla/firefox < 133.0
mozilla/thunderbird < 133.0
Published Nov 26, 2024
Tracked Since Feb 18, 2026