First published: Tue May 21 2019(Updated: )
If the ALT and "a" keys are pressed when users receive an extension installation prompt, the extension will be installed without the install prompt delay that keeps the prompt visible in order for users to accept or decline the installation. A malicious web page could use this with spoofing on the page to trick users into installing a malicious extension.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <67 | 67 |
Mozilla Firefox | <67.0 | |
debian/firefox | 133.0.3-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-11697 is a vulnerability in Mozilla Firefox that allows a malicious web page to install extensions without user consent.
CVE-2019-11697 has a severity score of 6.5, which is considered medium.
To fix CVE-2019-11697, update Mozilla Firefox to version 67.0 or higher.
You can find more information about CVE-2019-11697 on the Mozilla website and the Bugzilla entry.
CVE-2019-11697 is classified as CWE-20, which is Improper Input Validation.