First published: Thu Sep 28 2017(Updated: )
Last updated 24 July 2024
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <56 | 56 |
Mozilla Firefox | <=55.0.3 | |
debian/firefox | 131.0.2-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2017-7815.
The severity of CVE-2017-7815 is medium with a CVSS score of 5.3.
Mozilla Firefox versions up to and excluding 56, as well as some Ubuntu and Debian packages, are affected by CVE-2017-7815.
CVE-2017-7815 allows an attacker to create a modal dialog through JavaScript using the "data:" protocol, which can have an arbitrary domain as the dialog's location, spoofing the origin of the dialog from the user's view.
You can find more information about CVE-2017-7815 on Bugzilla (https://bugzilla.mozilla.org/show_bug.cgi?id=1368981), the Mozilla Security Advisories (https://www.mozilla.org/en-US/security/advisories/mfsa2017-21/), and SecurityFocus (http://www.securityfocus.com/bid/101057).