CVE-2017-7839

Source
https://cve.org/CVERecord?id=CVE-2017-7839
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7839.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-7839
Downstream
Related
Published
2018-06-11T21:29:11.780Z
Modified
2026-03-15T22:16:46.406101Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Control characters prepended before "javascript:" URLs pasted in the addressbar can cause the leading characters to be ignored and the pasted JavaScript to be executed instead of being blocked. This could be used in social engineering and self-cross-site-scripting (self-XSS) attacks where users are convinced to copy and paste text into the addressbar. This vulnerability affects Firefox < 57.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7839.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "56.0.2"
            }
        ]
    }
]