HTML injection in Mozilla Firefox - CVE-2017-5453
Published: April 19, 2017 / Updated: March 13, 2018
Mozilla Firefox
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a spoofing attack.
The vulnerability exists due to an insufficient sanitization of data sent as URL parameters for a feed's TITLE element during scrolling with editable content. A remote attacker can inject aritrary HTML code and perform XSS attack.