CVE-2017-5453 is a medium-severity vulnerability affecting Mozilla Firefox versions prior to 53, allowing for static HTML injection into the RSS reader preview page. This occurs due to improper escaping of characters in the "TITLE" element of a feed's URL parameters, enabling content spoofing. The attack requires user interaction (UI:R) but does not permit the execution of scripted content, limiting its impact to low integrity (I:L) with no confidentiality or availability impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 53.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 53CPE match | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.