CVE-2018-5135
CVSS v3.0
7.5 (High)
CVSS v2.0
5 (Medium)
EPSS
0.28 % (69th)
Affected Products
1
Advisories
3
WebExtensions can bypass normal restrictions in some circumstances and use "browser.tabs.executeScript" to inject scripts into contexts where this should not be allowed, such as pages from other WebExtensions or unprivileged "about:" pages. This vulnerability affects Firefox < 59.
Weaknesses
- CWE-862
- Missing Authorization
- CVE Status
- PUBLISHED
- CNA
- Mozilla Corporation
- Published Date
-
2018-06-11 21:29:14
(6 years ago) - Updated Date
-
2019-10-03 00:03:26
(5 years ago)
Affected Products
Loading...
Loading...
Loading...
Configuration #1
|
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...