Field Assessment
AI analysis pending.
CVE
CVE-2017-7791
Severity
MEDIUM
CVSS
5.3
EPSS
1.84%
Firefox
Original Filing — NVD Description
On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary domains following page navigation, spoofing of the origin of the modal alert from the iframe content. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.