CVE-2017-5458: XSS
Last updated 24 July 2024
Other sources
When a "javascript:" URL is drag and dropped by a user into the addressbar, the URL will be processed and executed. This allows for users to be socially engineered to execute an XSS attack on themselves. This vulnerability affects Firefox < 53.
— Launchpad
When a javascript: URL is drag and dropped by a user into the addressbar, the URL will be processed and executed. This allows for users to be socially engineered to execute an XSS attack on themselves.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-5433
- CVE-2017-5435
- CVE-2017-5436
- CVE-2017-5461
- CVE-2017-5459
- CVE-2017-5466
- CVE-2017-5434
- CVE-2017-5432
- CVE-2017-5460
- CVE-2017-5438
- CVE-2017-5439
- CVE-2017-5440
- CVE-2017-5441
- CVE-2017-5442
- CVE-2017-5464
- CVE-2017-5443
- CVE-2017-5444
- CVE-2017-5446
- CVE-2017-5447
- CVE-2017-5465
- CVE-2017-5448
- CVE-2016-10196
- CVE-2017-5454
- CVE-2017-5455
- CVE-2017-5456
- CVE-2017-5469
- CVE-2017-5445
- CVE-2017-5449
- CVE-2017-5450
- CVE-2017-5451
- CVE-2017-5462
- CVE-2017-5463
- CVE-2017-5467
- CVE-2017-5452
- CVE-2017-5453
- CVE-2017-5458
- CVE-2017-5468
- CVE-2017-5430
- CVE-2017-5429
Frequently Asked Questions
What is the severity of CVE-2017-5458?
CVE-2017-5458 is classified as a medium-severity vulnerability due to its potential for exploitation through social engineering tactics.
How do I fix CVE-2017-5458?
To mitigate CVE-2017-5458, users should upgrade their Firefox browser to version 53 or later.
What versions of Firefox are affected by CVE-2017-5458?
CVE-2017-5458 affects all versions of Firefox prior to version 53.
What type of attack does CVE-2017-5458 enable?
CVE-2017-5458 enables unsanctioned execution of JavaScript through drag-and-drop actions, facilitating self-inflicted XSS attacks.
Is there a workaround for CVE-2017-5458 if upgrading is not possible?
While there is no specific workaround for CVE-2017-5458, avoiding drag-and-drop of 'javascript:' URLs can help mitigate the risk.