Related Vulnerabilities: CVE-2021-38497  

Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to possible user confusion and spoofing attacks.

Severity Medium

Remote Yes

Type Content spoofing

Description

Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to possible user confusion and spoofing attacks.

AVG-2443 firefox 92.0.1-1 93.0-1 High Testing

https://www.mozilla.org/security/advisories/mfsa2021-43/
https://bugzilla.mozilla.org/show_bug.cgi?id=1726621