CVE-2017-5458: Mozilla Firefox
Medium severity, CVSS 6.1. EPSS: 1.4% chance of exploitation in the next 30 days.
When a "javascript:" URL is drag and dropped by a user into the addressbar, the URL will be processed and executed. This allows for users to be socially engineered to execute an XSS attack on themselves. This vulnerability affects Firefox < 53.
Affected products
- Mozilla Firefox: before 53.0 (fixed in 53.0)
Published 2018-06-11. Last modified 2026-06-17.