Severity
7.1HIGH
EPSS
0.1%
top 79.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 28
Latest updateMay 14

Description

A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 1.8 | Impact: 5.2

Affected Packages7 packages

CVEListV5mozilla/firefoxunspecified63
NVDmozilla/firefox< 60.3.0+1
CVEListV5mozilla/firefox_esrunspecified60.3
Debianfirefox-esr< 60.3.0esr-1+3

Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 18.04, 18.10, Enterprise Linux 7.5

🔴Vulnerability Details

3
GHSA
GHSA-xxh5-92qj-c4gh: A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being2022-05-14
CVEList
CVE-2018-12397: A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being2019-02-28
OSV
CVE-2018-12397: A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being2019-02-28

💥Exploits & PoCs

1
Exploit-DB
SEIG SCADA System 9 - Remote Code Execution2018-08-19

📋Vendor Advisories

3
Ubuntu
Firefox vulnerabilities2018-10-24
Red Hat
Mozilla: WebExtension local file permission check bypass2018-10-23
Debian
CVE-2018-12397: firefox - A WebExtension can request access to local files without the warning prompt stat...2018

💬Community

1
Bugzilla
CVE-2018-12397 Mozilla: WebExtension local file permission check bypass2018-10-23