6.8
CVSSv2

CVE-2018-12370

Published: 18/10/2018 Updated: 06/12/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

In Reader View SameSite cookie protections are not checked on exiting. This allows for a payload to be triggered when Reader View is exited if loaded by a malicious site while Reader mode is active, bypassing CSRF protections. This vulnerability affects Firefox < 61.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 18.04

canonical ubuntu linux 16.04

canonical ubuntu linux 14.04

canonical ubuntu linux 17.10

mozilla firefox

Vendor Advisories

Firefox could be made to crash or run programs as your login if it opened a malicious website ...
USN-3705-1 caused some minor regressions in Firefox ...
Mozilla Foundation Security Advisory 2018-15 Security vulnerabilities fixed in Firefox 61 Announced June 26, 2018 Impact critical Products Firefox Fixed in Firefox 61 ...
In Reader View SameSite cookie protections are not checked on exiting This allows for a payload to be triggered when Reader View is exited if loaded by a malicious site while Reader mode is active, bypassing CSRF protections This vulnerability affects Firefox &lt; 61 ...
In the Reader View of Firefox before 610, SameSite cookie protections are not checked on exiting This allows for a payload to be triggered when Reader View is exited if loaded by a malicious site while Reader mode is active, bypassing CSRF protections ...