Self-XSS in Mozilla Firefox - CVE-2017-5458
Published: April 19, 2017
Mozilla Firefox
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a psoofing attack.
The vulnerability exists due to an insufficient sanitization of data sent as URL, when a javascript: URL is drag and dropped by a user into the addressbar, the URL will be processed and executed. A remote attacker can trick the victim into executing malicious JavaScript.