383
VMScore

CVE-2017-7839

Published: 11/06/2018 Updated: 25/06/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Control characters prepended before "javascript:" URLs pasted in the addressbar can cause the leading characters to be ignored and the pasted JavaScript to be executed instead of being blocked. This could be used in social engineering and self-cross-site-scripting (self-XSS) attacks where users are convinced to copy and paste text into the addressbar. This vulnerability affects Firefox < 57.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

Vendor Advisories

Firefox could be made to crash or run programs as your login if it opened a malicious website ...
USN-3477-1 caused a regression in Firefox ...
USN-3477-1 caused some minor regressions in Firefox ...
USN-3477-1 caused a regression in Firefox ...
Mozilla Foundation Security Advisory 2017-24 Security vulnerabilities fixed in Firefox 57 Announced November 14, 2017 Impact critical Products Firefox Fixed in Firefox 57 ...
Control characters prepended before javascript: URLs pasted in the addressbar in Firefox before 570 can cause the leading characters to be ignored and the pasted JavaScript to be executed instead of being blocked This could be used in social engineering and self-cross-site-scripting (self-XSS) attacks where users are convinced to copy and paste t ...