ZeroHour

CVE-2018-5182

CVSS 3.0
7.5 high
EPSS
2%p80
Published
()
Modified
Description

If a text string that happens to be a filename in the operating system's native format is dragged and dropped onto the addressbar the specified local file will be opened. This is contrary to policy and is what would happen if the string were the equivalent "file:" URL. This vulnerability affects Firefox < 60.

Vendors
canonicalmozilla
Products
ubuntu linux, firefox
Weakness
CWE-200
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.