PT-2017-16511 · Mozilla+2 · Firefox+2

Jose María Acuña

·

Published

2017-04-19

·

Updated

2024-12-12

·

CVE-2017-5453

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 53
Description The issue is related to a mechanism that allows injecting static HTML into the RSS reader preview page. This is due to a failure to properly escape characters sent as URL parameters for a feed's TITLE element. The issue allows for spoofing, but it does not permit the execution of scripted content.
Recommendations For versions prior to 53, update to version 53 or later to resolve the issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1577
ALT-PU-2018-1854
CVE-2017-5453
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
USN-3260-1
USN-3260-2

Affected Products

Alt Linux
Firefox
Ubuntu