Control characters prepended before "javascript:" URLs pasted in the addressbar can cause the leading characters to be ignored and the pasted JavaScript to be executed instead of being blocked. This could be used in social engineering and self-cross-site-scripting (self-XSS) attacks where users are convinced to copy and paste text into the addressbar. This vulnerability affects Firefox < 57.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://bugzilla.mozilla.org/show_bug.cgi?id=1402896 | issue tracking permissions required |
https://www.mozilla.org/security/advisories/mfsa2017-24/ | vendor advisory |
http://www.securityfocus.com/bid/101832 | vdb entry third party advisory |
http://www.securitytracker.com/id/1039803 | vdb entry third party advisory |