Aller au contenu
appaloosa scout logo main rounded
MEDIUM 6.1

CVE-2017-5466

EN If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, triggering a reload will run the reloaded "data:text/html" page with its origin set incorrectly. This allows for a cross-site scripting (XSS) attack. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.

CVSS v3 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS 0.6% percentile 70.3%

Apps suivies affectées

Configurations CPE vulnérables

Vendor Produit Plateforme Versions CPE 2.3 URI
mozilla thunderbird Windows <52.1.0 cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Voir sur NVD ↗