First published: Tue Jan 24 2017(Updated: )
The "mozAddonManager" allows for the installation of extensions from the CDN for addons.mozilla.org, a publicly accessible site. This could allow malicious extensions to install additional extensions from the CDN in combination with an XSS attack on Mozilla AMO sites. This vulnerability affects Firefox < 51.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <51 | 51 |
Firefox | <51.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-5393 is classified as a moderate risk vulnerability that can allow the installation of malicious extensions.
To mitigate CVE-2017-5393, users should update their Mozilla Firefox to version 51 or higher.
CVE-2017-5393 affects Mozilla Firefox versions prior to 51.
Yes, CVE-2017-5393 can be exploited in combination with an XSS attack on Mozilla AMO sites.
CVE-2017-5393 can enable the installation of additional malicious extensions without user consent.