CVE-2017-5458Cross-site Scripting in Mozilla Firefox

CWE-79Cross-site Scripting10 documents7 sources
Severity
6.1MEDIUMNVD
OSV9.8
EPSS
0.6%
top 29.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 14

Description

When a "javascript:" URL is drag and dropped by a user into the addressbar, the URL will be processed and executed. This allows for users to be socially engineered to execute an XSS attack on themselves. This vulnerability affects Firefox < 53.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

debiandebian/firefox< firefox 52.0.1-1 (sid)
CVEListV5mozilla/firefoxunspecified53
NVDmozilla/firefox< 53.0
Ubuntumozilla/firefox< 53.0+build6-0ubuntu0.14.04.1+3

🔴Vulnerability Details

4
GHSA
GHSA-c2m7-wq23-rhm8: When a "javascript:" URL is drag and dropped by a user into the addressbar, the URL will be processed and executed2022-05-14
OSV
firefox regression2017-05-11
OSV
firefox vulnerabilities2017-04-21
OSV
CVE-2017-5458: When a "javascript:" URL is drag and dropped by a user into the addressbar, the URL will be processed and executed2017-04-20

📋Vendor Advisories

4
Ubuntu
Firefox regression2017-05-11
Ubuntu
Firefox vulnerabilities2017-04-21
Red Hat
Mozilla: Drag and drop of javascript: URLs can allow for self-XSS (MFSA 2017-11)2017-04-19
Debian
CVE-2017-5458: firefox - When a "javascript:" URL is drag and dropped by a user into the addressbar, the ...2017

💬Community

1
Bugzilla
CVE-2017-5458 Mozilla: Drag and drop of javascript: URLs can allow for self-XSS (MFSA 2017-11)2017-04-19