CVE-2024-9397

6.1MEDIUM

A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 12

Published: 10/1/2024Updated: 3/18/2025

Description

A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.

AI AnalysisPowered by AI

Affected Products

mozillafirefox
mozillafirefox_esr
mozillathunderbird
mozillathunderbird
129.0
mozillathunderbird
129.0
mozillathunderbird
129.0
mozillathunderbird
129.0
mozillathunderbird
129.0
mozillathunderbird
129.0

References