Spoofing attack in Mozilla Firefox - CVE-2018-12382

 

Spoofing attack in Mozilla Firefox - CVE-2018-12382

Published: September 6, 2018


Vulnerability identifier: #VU14640
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-12382
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to conduct spoofing attack on the target system.

The vulnerability exists due to an error when scrolling the loaded domain out of view to the right. A remote unauthenticated attacker can use a javascript: URI in concert with JavaScript to insert text before the loaded domain name and spoof the displayed addressbar URL  on Firefox for Android.


Affected software

Mozilla Firefox

How to mitigate CVE-2018-12382

Update to version 62.0.

Mozilla Firefox - update to 62.0

External References

Related Security Bulletins