CVE-2018-8278Authentication Bypass by Spoofing in Microsoft Edge

Severity
6.1MEDIUMNVD
EPSS
0.5%
top 33.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 11
Latest updateMay 13

Description

A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofing Vulnerability." This affects Microsoft Edge.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

CVEListV5microsoft/microsoft_edgeWindows 10 Version 1803 for 32-bit Systems, Windows 10 Version 1803 for x64-based Systems+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-jmg8-wcjf-qmf3: A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofing Vulnerability2022-05-13
CVEList
CVE-2018-8278: A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofing Vulnerability2018-07-11

💥Exploits & PoCs

1
Exploit-DB
OPAC EasyWeb Five 5.7 - 'biblio' SQL Injection2018-10-02

📋Vendor Advisories

1
Microsoft
Microsoft Edge Spoofing Vulnerability2018-07-10

🕵️Threat Intelligence

10
Krebs
Patch Tuesday, July 2018 Edition2018-07-11
Trendmicro
July Patch Tuesday: Large Adobe Security Update2018-07-11
Trendmicro
July Patch Tuesday: Large Adobe Security Update2018-07-11
Trendmicro
July Patch Tuesday: Large Adobe Security Update2018-07-11
Trendmicro
July Patch Tuesday: Large Adobe Security Update2018-07-11
CVE-2018-8278 — Authentication Bypass by Spoofing | cvebase