CVE-2018-5176
UNKNOWN
Published 2018-06-11T21:00:00
Actions:
No CVSS data available
Description
The JSON Viewer displays clickable hyperlinks for strings that are parseable as URLs, including "javascript:" links. If a JSON file contains malicious JavaScript script embedded as "javascript:" links, users may be tricked into clicking and running this code in the context of the JSON Viewer. This can allow for the theft of cookies and authorization tokens which are accessible to that context. This vulnerability affects Firefox < 60.
Available Exploits
No exploits available for this CVE.
Related News
No news articles found for this CVE.
Affected Products
Affected Versions:
References
Published: 2018-06-11T21:00:00
Last Modified: 2024-08-05T05:26:46.989Z
Copied to clipboard!