CVE-2017-7791
PoC —CVSS 3.0
5.3 medium
EPSS
2%p78
Published
()
Modified
Description
On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary domains following page navigation, spoofing of the origin of the modal alert from the iframe content. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
In the news0 stories
No ingested article mentions this CVE yet.