When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar. This can be used for spoofing the domain of the current page. This vulnerability affects Firefox < 54.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mozilla

Published: 2018-06-11T21:00:00

Updated: 2018-06-29T09:57:01

Reserved: 2017-04-12T00:00:00


Link: CVE-2017-7762

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-06-11T21:29:08.343

Modified: 2018-07-30T15:23:09.370


Link: CVE-2017-7762

JSON object: View

cve-icon Redhat Information

No data.

CWE