CVE-2017-5453Improper Input Validation in Mozilla Firefox

Severity
4.3MEDIUMNVD
OSV9.8
EPSS
0.5%
top 32.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 14

Description

A mechanism to inject static HTML into the RSS reader preview page due to a failure to escape characters sent as URL parameters for a feed's "TITLE" element. This vulnerability allows for spoofing but no scripted content can be run. This vulnerability affects Firefox < 53.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages4 packages

debiandebian/firefox< firefox 52.0.1-1 (sid)
CVEListV5mozilla/firefoxunspecified53
NVDmozilla/firefox< 53.0
Ubuntumozilla/firefox< 53.0+build6-0ubuntu0.14.04.1+3

🔴Vulnerability Details

4
GHSA
GHSA-88rc-c9h4-g333: A mechanism to inject static HTML into the RSS reader preview page due to a failure to escape characters sent as URL parameters for a feed's "TITLE" e2022-05-14
OSV
firefox regression2017-05-11
OSV
firefox vulnerabilities2017-04-21
OSV
CVE-2017-5453: A mechanism to inject static HTML into the RSS reader preview page due to a failure to escape characters sent as URL parameters for a feed's "TITLE" e2017-04-20

📋Vendor Advisories

4
Ubuntu
Firefox regression2017-05-11
Ubuntu
Firefox vulnerabilities2017-04-21
Red Hat
Mozilla: HTML injection into RSS Reader feed preview page through TITLE element (MFSA 2017-11)2017-04-19
Debian
CVE-2017-5453: firefox - A mechanism to inject static HTML into the RSS reader preview page due to a fail...2017

💬Community

1
Bugzilla
CVE-2017-5453 Mozilla: HTML injection into RSS Reader feed preview page through TITLE element (MFSA 2017-11)2017-04-19