Related Vulnerabilities: CVE-2017-7762  

A security issue has been found in Firefox < 54.0. When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar. This can be used for spoofing the domain of the current page.

Severity Medium

Remote Yes

Type Content spoofing

Description

A security issue has been found in Firefox < 54.0. When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar. This can be used for spoofing the domain of the current page.

AVG-302 firefox 53.0.3-1 54.0-1 Critical Fixed

16 Jun 2017 ASA-201706-19 AVG-302 firefox Critical multiple issues

https://www.mozilla.org/en-US/security/advisories/mfsa2017-15/#CVE-2017-7762
https://bugzilla.mozilla.org/show_bug.cgi?id=1358248