When a "javascript:" URL is drag and dropped by a user into the addressbar, the URL will be processed and executed. This allows for users to be socially engineered to execute an XSS attack on themselves. This vulnerability affects Firefox < 53.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jun 11, 2018 |
| Freebsd | — | Upgrade thunderbirdUpgrade linux-seamonkeyUpgrade seamonkeyUpgrade firefoxUpgrade firefox-esrUpgrade libxulUpgrade linux-firefoxUpgrade linux-thunderbird | Apr 20, 2017 | Apr 19, 2017 |
| Mfsa2017 10 | — | Upgrade to Mozilla Firefox version 53.0 | Jul 12, 2018 | Jun 11, 2018 |
| Suse | — | Upgrade mozillafirefox-translations-otherUpgrade mozillafirefox-translations-commonUpgrade mozillafirefox | May 20, 2018 | Apr 19, 2017 |
| Ubuntu | — | Upgrade firefox | Apr 21, 2017 | Apr 19, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub