CVE Database
/

CVE-2017-7815

Back to search

CVE-2017-7815

Published: Jun 11, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

On pages containing an iframe, the "data:" protocol can be used to create a modal dialog through Javascript that will have an arbitrary domains as the dialog's location, spoofing of the origin of the modal dialog from the user view. Note: This attack only affects installations with e10 multiprocess turned off. Installations with e10s turned on do not support the modal dialog functionality. This vulnerability affects Firefox < 56.

VendorProductVersions

Mozilla

Firefox

affected
unspecified - < 56

References

1039465
vdb-entry
x_refsource_SECTRACK
101057
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now