CVE-2017-7840 PUBLISHED

JavaScript can be injected into an exported bookmarks file by placing JavaScript code into user-supplied tags in saved bookmarks. If the resulting exported HTML file is later opened in a browser this JavaScript will be executed. This could be used in social engineering and self-cross-site-scripting (self-XSS) attacks if users were convinced to add malicious tags to bookmarks, export them, and then open the resulting file. This vulnerability affects Firefox < 57.

EPSS 0.63% · 70.2th percentile

Risk Scores

EPSS Score
0.63%
70.2th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSfirefox0, 41.0.2+build2-0ubuntu1, 42.0+build2-0ubuntu1
Ubuntu:14.04:LTSfirefox42.0+build2-0ubuntu0.14.04.1, 43.0+build1-0ubuntu0.14.04.1, 43.0.4+build3-0ubuntu0.14.04.1
Ubuntu:18.04:LTSfirefox0, 56.0+build6-0ubuntu1

Timeline

References

Open in Interactive Console →