A security issue has been found in Firefox versions prior to 63.0, where it is possible to inject stylesheets and bypass Content Security Policy (CSP) by using the reflected URL in some special resource URIs, such as chrome:.
A security issue has been found in Firefox versions prior to 63.0, where it is possible to inject stylesheets and bypass Content Security Policy (CSP) by using the reflected URL in some special resource URIs, such as chrome:.
https://www.mozilla.org/en-US/security/advisories/mfsa2018-26/#CVE-2018-12398 https://bugzilla.mozilla.org/show_bug.cgi?id=1460538 https://bugzilla.mozilla.org/show_bug.cgi?id=1488061