CVE-2017-7812 Information
Feb 14, 2021
cve
Description
If web content on a page is dragged onto portions of the browser UI such as the tab bar links can be opened that otherwise would not be allowed to open. This can allow malicious web content to open a locally stored file through \file:\ URLs. This vulnerability affects Firefox 56.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Reference
http://www.securityfocus.com/bid/101057 http://www.securitytracker.com/id/1039465 https://bugzilla.mozilla.org/show_bug.cgi?id=1379842 https://www.mozilla.org/security/advisories/mfsa2017-21/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
5.3
Share on: