Description
Manually dragging and dropping an Outlook email message into the browser will trigger a page navigation when the message's mail columns are incorrectly interpreted as a URL. *Note: this issue only affects Windows operating systems with Outlook installed. Other operating systems are not affected.*. This vulnerability affects Firefox ESR < 60.2 and Firefox < 62.
References (6)
Scores
CVSS v3
5.3
EPSS
0.0064
EPSS Percentile
70.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Details
CWE
CWE-610
Status
published
Products (1)
mozilla/firefox
< 60.2.0
Published
Oct 18, 2018
Tracked Since
Feb 18, 2026