CVE-2013-1727: Mozilla Firefox

Medium severity, CVSS 4.0. EPSS: 5.2% chance of exploitation in the next 30 days.

Mozilla Firefox before 24.0 on Android allows attackers to bypass the Same Origin Policy, and consequently conduct cross-site scripting (XSS) attacks or obtain password or cookie information, by using a symlink in conjunction with a file: URL for a local file.

Affected products

  • Mozilla Firefox: up to and including 23.0.1; version 19.0 only; version 19.0.1 only; version 19.0.2 only; version 20.0 only; version 20.0.1 only; …

Published 2013-09-18. Last modified 2026-06-16.