CVE-2018-5176
CVE-2018-5176
Vexday Risk Score
3Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS —EPSS 1.4%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
11 jun 2018Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
The JSON Viewer displays clickable hyperlinks for strings that are parseable as URLs, including "javascript:" links. If a JSON file contains malicious JavaScript script embedded as "javascript:" links, users may be tricked into clicking and running this code in the context of the JSON Viewer. This can allow for the theft of cookies and authorization tokens which are accessible to that context. This vulnerability affects Firefox < 60.
Produtos afetados
Mozilla · FirefoxQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →