CVE-2017-7839

EUVD-2017-16814
Control characters prepended before "javascript:" URLs pasted in the addressbar can cause the leading characters to be ignored and the pasted JavaScript to be executed instead of being blocked. This could be used in social engineering and self-cross-site-scripting (self-XSS) attacks where users are convinced to copy and paste text into the addressbar. This vulnerability affects Firefox < 57.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 69%
Affected Products (NVD)
VendorProductVersion
mozillafirefox
𝑥
≤ 56.0.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
firefox
sid
132.0.1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
artful
Fixed 57.0+build4-0ubuntu0.17.10.5
released
bionic
Fixed 57.0.1+build2-0ubuntu1
released
trusty
Fixed 57.0+build4-0ubuntu0.14.04.4
released
xenial
Fixed 57.0+build4-0ubuntu0.16.04.5
released
zesty
Fixed 57.0+build4-0ubuntu0.17.04.5
released