ZeroHour

CVE-2018-5111

CVSS 3.0
6.5 medium
EPSS
2%p74
Published
()
Modified
Description

When the text of a specially formatted URL is dragged to the addressbar from page content, the displayed URL can be spoofed to show a different site than the one loaded. This allows for phishing attacks where a malicious page can spoof the identify of another site. This vulnerability affects Firefox < 58.

Vendors
mozillacanonical
Products
firefox, ubuntu linux
Weakness
CWE-20
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.