ZeroHour

CVE-2018-5135

CVSS 3.0
7.5 high
EPSS
2%p73
Published
()
Modified
Description

WebExtensions can bypass normal restrictions in some circumstances and use "browser.tabs.executeScript" to inject scripts into contexts where this should not be allowed, such as pages from other WebExtensions or unprivileged "about:" pages. This vulnerability affects Firefox < 59.

Vendors
mozilla
Products
firefox
Weakness
CWE-862
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.