URLs using "javascript:" have the protocol removed when pasted into the addressbar to protect users from cross-site scripting (XSS) attacks, but if a tab character is embedded in the "javascript:" URL the protocol is not removed and the script will execute. This could allow users to be socially engineered to run an XSS attack against themselves. This vulnerability affects Firefox < 59.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade firefox-esrUpgrade linux-thunderbirdUpgrade linux-seamonkeyUpgrade thunderbirdUpgrade linux-firefoxUpgrade libxulUpgrade firefoxUpgrade waterfoxUpgrade seamonkey | Dec 10, 2025 | Mar 13, 2018 |
| Mfsa2018 06 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 59.0 | Jul 12, 2018 | Jun 11, 2018 |
| Suse | — | Upgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox | May 19, 2018 | Mar 14, 2018 |
| Ubuntu | — | Upgrade firefox | Apr 26, 2018 | Mar 14, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub