Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mozilla Firefox ESR和Mozilla Firefox 信息泄露漏洞
Vulnerability Description
Mozilla Firefox是美国Mozilla基金会开发的一款开源Web浏览器。Firefox ESR是Firefox的一个延长支持版本。 Mozilla Firefox 63之前版本和Firefox ESR 60.3之前版本中存在安全漏洞,该漏洞源于WebExtension在访问本地文件时,程序没有弹出警告对话框。远程攻击者可利用该漏洞使扩展在本地页面中运行脚本。
CVSS Information
N/A
Vulnerability Type
N/A