CVE-2017-5458: Mozilla Firefox

Medium severity, CVSS 6.1. EPSS: 1.4% chance of exploitation in the next 30 days.

When a "javascript:" URL is drag and dropped by a user into the addressbar, the URL will be processed and executed. This allows for users to be socially engineered to execute an XSS attack on themselves. This vulnerability affects Firefox < 53.

Affected products

  • Mozilla Firefox: before 53.0 (fixed in 53.0)

Published 2018-06-11. Last modified 2026-06-17.