CVE-2017-5389

MEDIUM

Firefox < 51.0 - Open Redirect via WebExtensions mozAddonManager API

Title source: llm
STIX 2.1

Description

WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests to redirect script loads to a malicious site. This allows a malicious extension to then install additional extensions without explicit user permission. This vulnerability affects Firefox < 51.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1037693
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/security/advisories/mfsa2017-01/
Exploit, Issue Tracking, Patch, Vendor Advisory x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=1308688
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/95763

Scores

CVSS v3 6.1
EPSS 0.0037
EPSS Percentile 59.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-601
Status published
Products (1)
mozilla/firefox < 51.0
Published Jun 11, 2018
Tracked Since Feb 18, 2026