CVE-2017-5393

Publication date

2018-06-11 21:00:00

Family

mozilla

State

PUBLISHED

Description

The "mozAddonManager" allows for the installation of extensions from the CDN for addons.mozilla.org, a publicly accessible site. This could allow malicious extensions to install additional extensions from the CDN in combination with an XSS attack on Mozilla AMO sites. This vulnerability affects Firefox < 51.