Related Vulnerabilities: CVE-2017-5458  

An issue has been found in Firefox < 53. When a javascript: URL is drag and dropped by a user into the addressbar, the URL will be processed and executed. This allows for users to be socially engineered to execute an XSS attack on themselves.

Severity Low

Remote No

Type Cross-site scripting

Description

An issue has been found in Firefox < 53. When a javascript: URL is drag and dropped by a user into the addressbar, the URL will be processed and executed. This allows for users to be socially engineered to execute an XSS attack on themselves.

AVG-249 firefox 52.0.2-1 53.0-1 Critical Fixed

21 Apr 2017 ASA-201704-6 AVG-249 firefox Critical multiple issues

https://www.mozilla.org/en-US/security/advisories/mfsa2017-10/#CVE-2017-5458
https://bugzilla.mozilla.org/show_bug.cgi?id=1229426