← back
CVE-2017-5386

CVE-2017-5386

EPSS 2.3%
WebExtension scripts can use the "data:" protocol to affect pages loaded by other web extensions using this protocol, leading to potential data disclosure or privilege escalation in affected extensions. This vulnerability affects Firefox ESR < 45.7 and Firefox < 51.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →