CVE-2018-5135

HIGH

Firefox < 59.0 - Missing Authorization for WebExtension Script Injection

Title source: llm
STIX 2.1

Description

WebExtensions can bypass normal restrictions in some circumstances and use "browser.tabs.executeScript" to inject scripts into contexts where this should not be allowed, such as pages from other WebExtensions or unprivileged "about:" pages. This vulnerability affects Firefox < 59.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/103386
Permissions Required x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=1431371
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1040514
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3596-1/
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/security/advisories/mfsa2018-06/

Scores

CVSS v3 7.5
EPSS 0.0096
EPSS Percentile 76.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-862
Status published
Products (1)
mozilla/firefox < 59.0
Published Jun 11, 2018
Tracked Since Feb 18, 2026