When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar. This can be used for spoofing the domain of the current page. This vulnerability affects Firefox < 54.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published: 2018-06-11T21:00:00

Updated: 2024-08-05T16:12:28.256Z

Reserved: 2017-04-12T00:00:00

Link: CVE-2017-7762

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-06-11T21:29:08.343

Modified: 2018-07-30T15:23:09.370

Link: CVE-2017-7762

cve-icon Redhat

Severity : Moderate

Publid Date: 2017-04-20T00:00:00Z

Links: CVE-2017-7762 - Bugzilla