CVE-2018-12402Origin Validation Error in Mozilla Firefox

Severity
6.5MEDIUMNVD
OSV8.8
EPSS
0.4%
top 41.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 28
Latest updateOct 15

Description

The internal WebBrowserPersist code does not use correct origin context for a resource being saved. This manifests when sub-resources are loaded as part of "Save Page As..." functionality. For example, a malicious page could recover a visitor's Windows username and NTLM hash by including resources otherwise unreachable to the malicious page, if they can convince the visitor to save the complete web page. Similarly, SameSite cookies are sent on cross-origin requests when the "Save Page As..." men

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

debiandebian/firefox< firefox 63.0-1 (sid)
CVEListV5mozilla/firefoxunspecified63
NVDmozilla/firefox< 63.0
Ubuntumozilla/firefox< 63.0.3+build1-0ubuntu0.14.04.1+5

Also affects: Ubuntu Linux 14.04, 16.04, 18.04, 18.10

🔴Vulnerability Details

4
GHSA
GHSA-ggqr-5458-x5c8: The internal WebBrowserPersist code does not use correct origin context for a resource being saved2022-05-13
OSV
firefox regressions2018-11-23
OSV
firefox vulnerabilities2018-10-24
OSV
CVE-2018-12402: The internal WebBrowserPersist code does not use correct origin context for a resource being saved2018-10-24

📋Vendor Advisories

4
Ubuntu
Firefox regressions2018-11-23
Ubuntu
Firefox vulnerabilities2018-10-24
Red Hat
firefox: WebBrowserPersist uses incorrect origin information2018-10-23
Debian
CVE-2018-12402: firefox - The internal WebBrowserPersist code does not use correct origin context for a re...2018

💬Community

3
HackerOne
SameSite restrictions are lifted, and SameSite:Strict cookie are being sent.2025-10-15
Bugzilla
CVE-2018-12402 firefox: WebBrowserPersist uses incorrect origin information2019-04-04
Bugzilla
Saving web page embedding file: resources allows accessing SMB resources2018-03-19